Mythos found the Rejetto HFS flaw, and attackers probed it within a day of the write-up
An Anthropic Mythos-assisted find, CVE-2026-61500, was fixed in July, but scanning began about a day after Horizon3 published the details. The model did the finding; slow patching created the exposure.
By Zain
Published

Mythos found the Rejetto HFS flaw, and attackers were probing unpatched servers within about a day of the public write-up. That is the headline, and it is real. The more useful reading is narrower: an AI model found a subtle bug that the vendor fixed in July, and the exploitation window opened only when the technical details went public. The model did the finding. Slow patching did the damage.
What Mythos found
The bug is tracked as CVE-2026-61500, a critical authentication bypass in Rejetto HTTP File Server, an open-source tool for sharing files from a PC or server. It affects versions 3.0.0 through 3.2.0 and carries a CVSS score of 9.3, according to the VulnCheck advisory.
The mechanism is a chain. HFS signs its session cookies with a key derived from JavaScript's Math.random(), which is not designed for security and whose internal state can be reconstructed from its outputs. Separately, the server hands those raw outputs to unauthenticated visitors during login. Collect a few of them, solve for the generator's state, recover the signing key, and you can forge an administrator cookie. From there a configuration feature gives remote code execution.
Horizon3.ai, a penetration-testing firm that participates in Anthropic's Project Glasswing, ran Mythos against the code. Its write-up says the model connected the two weaknesses on its own and worked out that the leaked values were exactly what state recovery needed. The Register, citing researcher Zach Hanley, reports that Mythos proposed using the Z3 solver to recover the seed.
The timeline, and where sources disagree
The dates matter here, because the story only works if you read them carefully.
“Mythos identified off the bat that recovering the cryptographic seed was viable and how it would practically attack it”
- July 13, 2026: Rejetto released HFS 3.2.1. Its release notes say multiple vulnerabilities in all previous versions could let an attacker gain administrative access, and credit Hanley working with Claude and Anthropic Research. The VulnCheck advisory carries the same July 13 date.
- Late September 2026: Horizon3 published its technical write-up. The page itself shows September 30. Some outlets place the write-up or disclosure on October 1 or 2, so treat the exact day as unsettled.
- Within roughly 24 hours of the write-up: VulnCheck canary systems, which are decoy servers it uses to watch for scanning, recorded an actor on China-hosted infrastructure targeting vulnerable hosts in the US and Japan. The Register and SecurityWeek both report this. Further hits through proxies followed a day later.
So the fix existed for about eleven weeks before the public explanation, and the explanation turned into attacks almost immediately. Nobody has shown that the attackers used AI, and no source we opened claims they did. What the record shows is a detailed public write-up, then scanning.

What this does and does not show about Mythos
It shows capability on a hard kind of problem. Spotting a weak random number generator is routine for scanners. Noticing that a second code path leaks its outputs, and that a constraint solver can turn those outputs into a key, is multi-step reasoning across files. Horizon3 credits the model's mathematical reasoning for that step, and said it needed no extra prompting. That is a vendor-side account from a partner with an interest in the tool looking good, and we have not seen the transcript.
It does not show a flood of exploited AI-found bugs. Patrick Garrity's public tracker of Anthropic-credited CVEs listed 300 entries as of its October 2 update, and The Register's account says only one earlier entry had been exploited in real attacks, a figure we could not confirm on the tracker page itself. Two exploited cases out of hundreds is a data point about timing, not a rate.
It also shows something about the people on the defending side. Glasswing is a defender program: Horizon3 found the flaw, reported it, and the maintainers shipped a fix months before details went public. The system did what coordinated disclosure is supposed to do. The failure came after, in the gap between a patch existing and a patch being installed on internet-facing file servers that nobody was watching.
Why the window keeps shrinking
This is the same pattern we covered in Microsoft's 2026 defense report: vulnerabilities are weaponized in under a day while patching takes weeks. A public write-up now works as an attack manual for anyone with a scanner. When AI models also write the write-ups faster, find more bugs, and explain the exploit chain clearly, the defender's margin between "patch released" and "details published" is the only slack left.
There is also a policy question about gated access to strong cyber models. Anthropic and its partners limit who gets Mythos precisely so findings reach maintainers first. That worked here for discovery. It does not control what happens once a human researcher publishes the details, and it was never designed to. For the broader debate on who should get such models first, see our piece on Gemini 4 Argon going to cyber defenders first.
What to do if you run HFS
Check the version. Anything from 3.0.0 through 3.2.0 should be upgraded to 3.2.1 or later, and any instance exposed to the internet that was not upgraded before the write-up should be treated as possibly compromised: rotate secrets, review the server configuration for unexpected code, and check logs for forged admin sessions. For everyone else, the lesson is about speed. Software that sits on the public internet and has a security fix available needs to be updated before the write-up lands, not after.
Our take
The strongest claim here is the modest one: a model found a real, critical flaw that a human team then fixed. The weakest claim is any suggestion that AI-speed attackers have arrived, because the evidence is a quick scan after a public write-up, not a demonstrated AI attack. What to watch is whether more Glasswing findings show up in exploitation data, and whether labs and partners start delaying write-ups until patch adoption is higher. Until then, the practical rule is plain: patch before the blog post.
Frequently asked questions
Did Anthropic's Mythos find the Rejetto HFS vulnerability?
Yes, per Horizon3.ai, which used Mythos through Project Glasswing and credits the model with linking a weak Math.random() signing key to a separate leak of its outputs. The HFS release notes credit Zach Hanley of Horizon3 working with Claude and Anthropic Research. The flaw is CVE-2026-61500.
What is CVE-2026-61500?
A critical authentication bypass in Rejetto HFS 3.0.0 through 3.2.0, CVSS 9.3 per VulnCheck. Session cookies are signed with a key derived from Math.random(), and the server leaks outputs of that generator at login, letting an attacker forge an admin cookie and reach remote code execution.
Was the Rejetto HFS flaw really exploited within a day?
VulnCheck canary systems recorded scanning from China-hosted infrastructure about a day after Horizon3 published its write-up, per The Register and SecurityWeek. Outlets differ on exact dates, and none we opened shows the attackers used AI.
Is there a patch for the Rejetto HFS flaw?
Yes. HFS 3.2.1, released July 13, 2026, fixes it. The fix existed about eleven weeks before the write-up, so the exposure was unpatched servers, not an unfixed bug.
Does this prove AI has broken responsible disclosure?
No. The case shows a patched bug being scanned for after a detailed public write-up. That is an old pattern. A public tracker lists 300 Anthropic-credited CVEs, and The Register says only one earlier entry had been exploited, so a handful of cases is not a rate.
What should HFS users do now?
Upgrade to 3.2.1 or later. Treat any internet-exposed instance on an older version as possibly compromised: rotate secrets, review server configuration for unexpected code, and check logs for forged admin sessions.
Sources
What each one is, and whose it is.
- 1
Anthropic Mythos Discovers Rejetto HFS Authentication Bypass, Horizon3.ai (September 29, 2026)
Vendor announcement - 2
Rejetto HFS session forgery via predictable signing key, VulnCheck (July 12, 2026)
DocumentationIndependent of the vendor - 3
HFS release 3.2.1, Rejetto, GitHub (July 12, 2026)
DocumentationIndependent of the vendor - 4
Anthropic's super bug-hunting model Mythos is hardcore good at math, as latest vuln under attack shows, The Register (October 2, 2026)
Press reportIndependent of the vendor - 5
Exploitation hits Rejetto HFS vulnerability discovered by AI, SecurityWeek (October 2, 2026)
Press reportIndependent of the vendor - 6
Anthropic-Credited-CVEs tracker, Patrick Garrity, GitHub (October 1, 2026)
DatasetIndependent of the vendor