# Attackers exploit Mythos-found Rejetto HFS flaw within a day

> Attackers exploited critical Rejetto HFS flaw CVE-2026-61500, found with Anthropic's Mythos, about a day after a write-up.

*CVE-2026-61500, a critical bug in Rejetto HTTP File Server, was targeted about 24 hours after a public technical write-up.*

By Behzad Hosseini · FeaturedDaily
Canonical: https://featureddaily.com/news/attackers-exploit-mythos-found-rejetto-hfs-flaw-within-a-day

**What happened:** Attackers began exploiting CVE-2026-61500, a critical flaw in Rejetto HTTP File Server (HFS), within about a day of a public technical write-up. Researchers at Horizon3.ai found the bug using Anthropic's Mythos model, [SecurityWeek reported](https://www.securityweek.com/exploitation-hits-rejetto-hfs-vulnerability-discovered-by-ai/).

**The numbers:** The flaw scores 9.3 on the CVSS scale. It was discovered in June 2026, and HFS 3.2.1 patched it on 13 July. VulnCheck saw exploitation attempts from a China Telecom IP address against canaries in Japan and the US on 2 October. Four US-based IPs followed.

**The details:** HFS used JavaScript's Math.random() to make session-cookie values. That generator, xorshift128+, is reversible. An attacker who collects login responses can reconstruct its state and recover the signing key. From there, they can forge administrator session cookies and get remote code execution.

**In their words:** Horizon3.ai said attackers "able to collect other numbers generated by Math.random() could determine other generated numbers and forge the authentication cookies."

**The context:** Zach Hanley of Horizon3.ai led the work. Mythos used "advanced mathematical reasoning to recognize that Math.random() PRNG outputs could be reversed to reconstruct the secret session-cookie signing key." Mythos is Anthropic's restricted cyber-capable model. Rejetto's advisory says: "Multiple security vulnerabilities have been found in all previous versions, potentially allowing an attacker to gain administrative access to HFS."

**Why it matters:** The gap between disclosure and attack was about 24 hours, according to a [DEV Community report](https://dev.to/techaiwire/rejetto-hfs-cve-2026-61500-exploited-a-day-after-write-up-35oc). The Register called it the second Anthropic-linked vulnerability exploited in the wild, under a headline saying Mythos is "hardcore good at math".

**The rivals:** Google's Gemini 4 Argon launched to cyber defenders the same week.

**What's next:** Anyone running HFS should upgrade to version 3.2.1 or later. All earlier versions are affected.

## Key takeaways

- Exploitation began about 24 hours after the write-up
- CVE-2026-61500 scores 9.3 and allows remote code execution
- Upgrade to HFS 3.2.1 or later

## Sources

- [Exploitation Hits Rejetto HFS Vulnerability Discovered by AI](https://www.securityweek.com/exploitation-hits-rejetto-hfs-vulnerability-discovered-by-ai/) — SecurityWeek, 2026-10-05
- [Rejetto HFS CVE-2026-61500 exploited a day after write-up](https://dev.to/techaiwire/rejetto-hfs-cve-2026-61500-exploited-a-day-after-write-up-35oc) — DEV Community, 2026-10-04
