Anthropic Mythos finds critical HFS bug, exploited within a day
Horizon3 used Anthropic Mythos to find CVE-2026-61500 in Rejetto HFS. VulnCheck saw exploitation within about a day. Patch to 3.2.1+.

Anthropic's restricted bug hunting model Mythos, used by Horizon3 under Project Glasswing, found a critical flaw in Rejetto HTTP File Server. The bug is tracked as CVE-2026-61500. Within about a day of disclosure, VulnCheck reported real world exploitation against hosts in the US and Japan. The Register covered the timeline on 3 October 2026.
What happened
Horizon3 researcher Zach Hanley wrote that Mythos chained two problems in HFS 3.x. The server signed session cookies with a key built from Math.random(), which in V8 is the reversible xorshift128+ generator. Separately, a login path leaked raw Math.random() outputs to clients. Together, that made it possible to recover the signing key, forge an admin session, and reach remote code execution through built in admin features.
Horizon3 published a detailed technical write up. The Register confirmed that VulnCheck saw exploitation start the evening after disclosure, first from a China hosted IP hitting US and Japan targets, then further hits that looked like proxy traffic. The fix is Rejetto HFS 3.2.1 or later. Anthropic keeps Mythos off general release and offers it only to selected partners in Project Glasswing. Garrity's tracker put Mythos and Glasswing related finds in the hundreds of CVEs, with this case as the second known Anthropic linked vulnerability under active exploitation.
Why it matters
AI assisted vulnerability research is no longer only a lab demo. A model that can spot crypto mistakes, link them to a leak, and help build a working chain shortens the path from research to weaponization. Defenders get the same tools, but attackers can move just as fast once a CVE is public. File servers that sit on the open internet with weak session crypto become easy targets in that window.
It also shows why "too powerful to ship widely" models still reshape the landscape: partners using them for defense still publish findings that the wider attacker community can copy within hours.
Dany's take
If you run Rejetto HFS, patch to 3.2.1 now and lock admin access behind a strong network boundary. For everyone else, treat this as a reminder that disclosure day is not a quiet day. AI will keep finding deeper bug classes, so patch speed and exposure reduction matter more than ever. I will keep watching Project Glasswing disclosures and how fast follow on exploitation shows up.
Source: The Register: Anthropic Mythos and Rejetto HFS under attack. Primary disclosure: Horizon3: Anthropic Mythos Finds Rejetto HFS RCE.
Source: theregister.com