Threat · curated 3 Oct 2026

Anthropic's super bug-hunting model Mythos is hardcore good at math, as latest vuln under attack shows

Dossier

Coverage timeline

discovered horizon3.ai primary 3 Oct 2026theregister.com

Single-source incident — first reported, latest, and curated coincide.

Why it matters

CVE-2026-61500 illustrates how AI models like Anthropic's Mythos are now surfacing exploitable 0-days that attackers weaponize almost immediately, compressing the window defenders have to patch.

CVE-2026-61500, a critical authentication-bypass bug in Rejetto HTTP File Server (HFS) that enables full admin access and remote code execution, was discovered by Horizon3 researcher Zach Hanley using Anthropic's Mythos bug-hunting model and came under active exploitation within a day of disclosure. VulnCheck's canaries detected a China-hosted IP targeting vulnerable hosts in the US and Japan; a public exploit video was also published, and users should update to HFS v3.2.1 or later.

exploited-vuln

Summary

CVE-2026-61500 is a critical authentication-bypass vulnerability in the open-source Rejetto HTTP File Server (HFS) that can lead to full administrative access and remote code execution. It was discovered by Horizon3 researcher Zach Hanley using Anthropic's Mythos bug-hunting model and reported to VulnCheck for CVE assignment.[1]

The CVE came under active exploitation within roughly a day of disclosure. VulnCheck canaries detected an actor in China targeting real vulnerable hosts in the US and Japan, and subsequent activity was observed from US-based proxy IP addresses. This made it the second Anthropic/Mythos-linked vulnerability known to have been exploited in the wild out of 286 CVEs credited to the program.[1]

Defenders running Rejetto HFS should update to v3.2.1 or later, which fixes this and other security flaws.[1]

Attack chain

  1. Reconnaissance: An actor scanned for and targeted real vulnerable Rejetto HFS hosts, detected by VulnCheck canaries targeting servers in the US and Japan.[1]
  2. Session key recovery: The attacker leverages leaked Math.random() outputs and V8's reversible xorshift128+ PRNG to recover the PRNG seed (demonstrated via the Z3 SMT solver), deriving the session signing key used by Koa/keygrip.[1]
  3. Authentication bypass: With the recovered signing key, the attacker forges valid session cookies to bypass authentication and obtain full admin access.[1]
  4. Remote code execution: Admin access on HFS is leveraged to remotely execute code on the server, as demonstrated in Hanley's published exploitation video.[1]

Disclosure timeline

DateEvent
2024Rejetto HFS appeared on CISA's Known Exploited Vulnerabilities catalog for an earlier flaw.[1][2]
April 2026Anthropic announced Project Glasswing, giving select partners access to the Mythos bug-hunting model.[1]
July 2026Horizon3 joined Project Glasswing and began using Mythos in its vulnerability research.[1]
Wednesday (circa Sept 30, 2026)Horizon3's Zach Hanley published the discovery of CVE-2026-61500 and a video demonstrating exploitation.[1]
Thursday (circa Oct 1, 2026)VulnCheck detected in-the-wild exploitation of CVE-2026-61500, with activity from an IP in China targeting vulnerable hosts in the US and Japan.[1]
Friday (circa Oct 2, 2026)VulnCheck observed four additional hits originating from two US IP addresses in the same subnet, appearing to come from a proxy.[1]

How it works

HFS authentication depends on a random value generated with Math.random() that is passed to the Koa Node.js framework, where keygrip uses it to sign all session cookies. If an attacker can derive the session signing key, they can forge valid session cookies and bypass authentication.[1]

This should be safe if Math.random() uses a secure PRNG, but V8's Math.random() implementation used the xorshift128+ algorithm, whose output is fully reversible. The application also leaked raw Math.random() outputs through a separate code path, and Mythos recognized these two facts as a chain. Its analysis claimed the Z3 SMT solver could recover the PRNG seed from the leaked observations, making session key recovery feasible and enabling RCE.[1]

Affected versions and patch status

ProductAffectedPatch status
Rejetto HTTP File Server (HFS)Versions prior to v3.2.1Fixed in v3.2.1 and later[1]

Indicators of Compromise

TypeIndicatorContext
cveCVE-2026-61500Critical authentication-bypass vulnerability in Rejetto HFS under active exploitation.[1]
ip173.239.211.248US-based IP observed by VulnCheck exploiting CVE-2026-61500; same subnet as .249 and appears to be a proxy.[1]
ip173.239.211.249US-based IP observed by VulnCheck exploiting CVE-2026-61500; same subnet as .248 and appears to be a proxy.[1]

Key takeaways

  • An AI bug-hunting model (Mythos) chained an insecure, reversible PRNG with a separate information leak and an SMT solver to recover a session signing key and bypass authentication — a technique Horizon3 researchers had not seen used against a cryptographic flaw in a real application.[1]
  • Disclosure of CVE-2026-61500 was followed by in-the-wild exploitation within about a day, underscoring the need to patch internet-facing Rejetto HFS instances immediately.[1]

Defensive actions

  • Update Rejetto HFS to v3.2.1 or later.: This release fixes CVE-2026-61500 and other security flaws being actively exploited.[1]
  • Monitor for and block exploitation traffic from the observed proxy IP addresses.: VulnCheck observed exploitation hits from 173.239.211.248 and 173.239.211.249, which appear to be proxies, as well as initial activity from a China-hosted IP.[1]