Post-Cutoff.com
  1. Home
  2. Timeline
  3. 2026
  4. Mythos-found Rejetto HFS auth bypass (CVE-2026-61500) is…

Mythos-found Rejetto HFS auth bypass (CVE-2026-61500) is exploited in the wild a day after disclosure

★★after cutoffpolicy-safetyAnthropicHorizon3.aiconfidence: high

On Sept 30, 2026 Horizon3.ai disclosed CVE-2026-61500, a critical authentication bypass leading to RCE in Rejetto HTTP File Server 3.x, found by a Horizon3 analysis agent running Claude Mythos. Mythos chained an insecure Math.random()-based session key with a separate leak of raw PRNG outputs and proposed recovering the xorshift128+ state with a Z3 solver. Exploitation began the next day, and The Register said it was only the second of 286 Mythos/Glasswing CVEs known to be exploited.

Key facts

What happened

A security firm using Mythos through its own analysis harness found a cryptographic bug chain in a popular small file server, published it with a fix available, and attackers began exploiting it within about a day.

Why it matters

It shows both sides of AI vulnerability discovery: the model found a multi-step maths-heavy bug that humans said they would likely have skipped, and the gap between disclosure and exploitation was about a day.

Changelog

  • 2026-10-04: created (sweep 2026-10-04: The Register)

Related events

  1. Anthropic reveals Claude Mythos Preview, withholds it over cyber risk and launches Project Glasswing ★★★★★
  2. Anthropic releases Claude Fable 5.1 and Claude Mythos 5.1 ★★★★★

Sources (2)

id: 2026-09-30-mythos-rejetto-hfs-cve-exploited · updated 2026-10-04 · open in the interactive timeline