Found by AI, Weaponized in a Day: Mythos-Discovered Rejetto HFS Flaw Under Active Attack
CVE-2026-61500, a Rejetto HFS session-forgery flaw discovered by Anthropic's Mythos model, is being exploited in the wild by a China-based actor within 24 hours of disclosure.
A vulnerability discovered by an AI model is now being exploited by real attackers — and the timeline between disclosure and weaponization was less than a day.
On October 3, The Register reported that CVE-2026-61500, a critical authentication-bypass flaw in Rejetto HTTP File Server (HFS), is under active exploitation. VulnCheck’s Canary Intelligence sensors detected probes from a China-hosted IP against vulnerable US hosts within 24 hours of Horizon3’s technical disclosure on September 30, followed by additional scanning from four US-based IPs on Friday. It is the second vulnerability linked to Anthropic’s models known to be exploited in the wild — and the clearest demonstration yet of what happens when AI-accelerated vulnerability research meets AI-accelerated exploitation.
The bug: old-school crypto mistake, AI-grade discovery
The flaw itself is almost quaint. Rejetto HFS, an open-source file-sharing server used by thousands of small teams and homelab operators, signs its session cookies with a key derived from JavaScript’s Math.random(). In V8, Node.js’s JavaScript engine, Math.random() is implemented with the xorshift128+ algorithm — fast, non-cryptographic, and critically, reversible. Given enough consecutive outputs, an attacker can reconstruct the generator’s internal state and step it backwards in time.
HFS made two compounding mistakes. When the administrator hasn’t set COOKIE_SIGN_KEYS, the cookie-signing key is randomId(30), built from three consecutive Math.random() calls at process start. Worse, during the login handshake, the loginSrp1 endpoint stores a raw Math.random() value as a session id — and because koa-session cookies are base64 JSON (signed, not encrypted), the client receives the exact 52-bit double in its own Set-Cookie header. The server was handing attackers the observations they needed for free.
What makes this story remarkable is who found it. Horizon3 researcher Zach Hanley was running Anthropic’s Mythos model — the security-specialized variant the lab developed under Project Glasswing, its mission to secure the world’s most critical software — in a parallel harness of specialized vulnerability-hunting agents. The cryptographic weakness agent identified the insecure PRNG usage, separately spotted the Math.random() leak through the login path, recognized the two facts as an exploitable chain, and then did something human researchers routinely don’t do: it fully implemented the Z3 SMT solver attack, stepped the recovered state backwards to the signing key generated at startup, forged a valid administrator session cookie, and demonstrated arbitrary command execution. Twelve leaked login values were enough.
From disclosure to KEV in 72 hours
The exploitation timeline compresses the traditional window from months to hours. Horizon3 published its full technical write-up, including the exploit chain, on September 30. The fix itself was old news — Rejetto shipped HFS 3.2.1 back on July 13, 79 days before the write-up, and the VulnCheck advisory crediting “Zach Hanley of Horizon3.ai, in collaboration with Claude and Anthropic Research” dates to the same period. But detailed technical disclosure is a different signal from a patch notice: it tells attackers exactly what to look for and confirms the bug is real.
VulnCheck’s canary network — globally deployed internet sensors designed to catch the first signs of exploitation — detected probes for CVE-2026-61500 from a China-based actor within 24 hours of the Wednesday disclosure. By Friday, four US-based IPs had joined. VulnCheck’s Caitlin Condon flagged the new KEV (Known Exploited Vulnerabilities) entry, and the advisory now sits in the VulnCheck KEV database with a CVSS 4.0 score of 9.3 (CVSS 3.1: 9.8). Affected versions span HFS 3.0.0 through 3.2.0, the TypeScript rewrite of the older Delphi codebase — which itself had a prior KEV entry in 2024 for CVE-2024-23692.
The economics argument that should worry everyone
Hanley’s write-up contains the line that security economists will be quoting for a while: “Mythos negates both of those reasons.” He’s referring to the two classic justifications for leaving cryptographic flaws unexplored — lack of mathematics expertise and the time-and-economic-viability calculus that deprioritizes bugs requiring deep investment to weaponize.
A PRNG state-recovery attack is textbook cryptanalysis with public tooling. Mythos’s own analysis called it “standard publicly-tooled Z3/algebraic attack from ~3–5 consecutive doubles.” Humans have known about xorshift128+‘s invertibility for years; what was missing was the marginal cost of turning that knowledge into a working exploit against a specific application. Horizon3’s researchers write that they “do not recall ever seeing an SMT solver being used to attack a cryptographic flaw like this in a real application.” Now the capability sits in an automated harness that can sweep entire codebases overnight.
The defensive implications cut both ways, of course. Project Glasswing has surfaced more than ten thousand high- or critical-severity vulnerabilities across its roughly 50 partners since launching — bugs that got fixed before criminals found them. This particular flaw was patched 79 days before the public write-up. Used defensively, AI vulnerability research closes windows. But the same write-up that celebrates the discovery also serves as exploitation documentation, and the one-day gap to in-the-wild attacks shows how quickly adversaries metabolize it.
What defenders should do now
The guidance is straightforward but urgent. Upgrade Rejetto HFS to 3.2.1 or later — every 3.x release from 3.0.0 to 3.2.0 is affected. Set COOKIE_SIGN_KEYS to a long random secret so the signing key never derives from Math.random() at all, and restart after upgrading to invalidate any cookies forged against the old key. Do not expose the HFS admin interface to the internet; the final exploitation step requires the admin API’s custom-endpoint feature, which executes arbitrary JavaScript, so restricting it to a trusted network breaks the chain even if a cookie is forged. Review admin-defined endpoints on exposed instances for anything unfamiliar.
And the broader lesson extends well beyond HFS: audit your own code for Math.random() in security roles. Session ids, reset tokens, API keys, and signing keys belong to crypto.randomBytes() or crypto.randomUUID(). A bug class that used to be too expensive to chase is now something an AI harness can sweep for at scale — and as of this week, something attackers can weaponize from public disclosure in under 24 hours.
Sources
- [1] https://horizon3.ai/attack-research/disclosures/anthropic-mythos-rejetto-hfs-rce/
- [2] https://www.theregister.com/security/2026/10/03/anthropics-super-bug-hunting-model-mythos-is-hardcore-good-at-math-as-latest-vuln-under-attack-shows/5300933
- [3] https://www.vulncheck.com/advisories/rejetto-hfs-session-forgery-via-predictable-signing-key
- [4] https://threatfrontier.com/articles/mythos-rejetto-hfs-cve-2026-61500-math-random-admin-cookie
- [5] https://windowsforum.com/news/cve-2026-61500-attackers-exploit-rejetto-hfs-session-forgery-rce-upgrade-to-3-2-1.447112/