Mythos-found Rejetto HFS auth bypass (CVE-2026-61500) is exploited in the wild a day after disclosure
On Sept 30, 2026 Horizon3.ai disclosed CVE-2026-61500, a critical authentication bypass leading to RCE in Rejetto HTTP File Server 3.x, found by a Horizon3 analysis agent running Claude Mythos. Mythos chained an insecure Math.random()-based session key with a separate leak of raw PRNG outputs and proposed recovering the xorshift128+ state with a Z3 solver. Exploitation began the next day, and The Register said it was only the second of 286 Mythos/Glasswing CVEs known to be exploited.
Key facts
- Disclosure: Horizon3.ai (Zach Hanley), Sept 30, 2026; affects Rejetto HFS 3.x (TypeScript rewrite); The Register says upgrade to v3.2.1 or later
- Mythos noted that 'consecutive doubles allow xorshift128+ state recovery (standard Z3/algebraic tooling)' and that the app leaked raw Math.random() outputs, so session cookies could be forged for admin access
- Horizon3: its human researchers chose targets and validated findings, and said that without the model they would likely have dropped this kind of cryptographic bug for lack of time and maths expertise
- Exploitation from Thursday evening (Oct 1), first from a China-hosted IP against US and Japanese servers, then from US proxy IPs (The Register, citing VulnCheck's Patrick Garrity)
- As of Oct 2, Mythos and Project Glasswing were credited with 286 CVEs, and only one had previously been exploited in real-world attacks (The Register)
What happened
A security firm using Mythos through its own analysis harness found a cryptographic bug chain in a popular small file server, published it with a fix available, and attackers began exploiting it within about a day.
Why it matters
It shows both sides of AI vulnerability discovery: the model found a multi-step maths-heavy bug that humans said they would likely have skipped, and the gap between disclosure and exploitation was about a day.
Changelog
- 2026-10-04: created (sweep 2026-10-04: The Register)
Related events
- Anthropic reveals Claude Mythos Preview, withholds it over cyber risk and launches Project Glasswing ★★★★★
- Anthropic releases Claude Fable 5.1 and Claude Mythos 5.1 ★★★★★
Sources (2)
- officialHorizon3.ai: Anthropic Mythos discovers Rejetto HFS RCE (CVE-2026-61500)
- pressThe Register: Anthropic's super bug-hunting model Mythos is hardcore good at math, as latest vuln under attack shows (Oct 3)
id: 2026-09-30-mythos-rejetto-hfs-cve-exploited · updated 2026-10-04 · open in the interactive timeline