Real-world attacks have been confirmed against a vulnerability in the file-sharing software Rejetto HFS (CVE-2026-61500), a flaw that Anthropic's restricted AI model Mythos reportedly helped uncover. Exploitation is said to have begun roughly one day after security firm Horizon3 published a technical write-up. It is drawing attention as a case where an AI-found bug turned into real harm within a very short time.
What happened
The issue is an authentication-bypass vulnerability in Rejetto HFS (HTTP File Server) versions 3.0.0 through 3.2.0. It can give an attacker administrator access and allow arbitrary code execution on the server, so it is rated Critical, the highest severity tier. Its CVSS scores are reported as 9.8 under version 3.1 and 9.3 under version 4.0.
The CVE itself was published on July 13, 2026, and a fixed release, 3.2.1, was already available. From late September into early October, a proof of concept and detailed write-ups began circulating, followed by observed attacks. The exact dates of the write-up and the first observed attack vary by a few days depending on the source, so the one point to keep in mind here is that attacks came about one day after the write-up.
The root cause was how HFS created the key that signs session cookies after login. HFS generated the key with JavaScript's Math.random(). That function runs on the V8 engine's xorshift128+ algorithm, which is fast but unsuitable for cryptography, because its internal state can be worked out from its output.
On top of that, the random values leaked to clients during the pre-login exchange. An attacker could read values from a legitimately issued cookie and feed them as constraints to Microsoft's Z3 solver. That recovers the generator's internal state, lets the attacker step back to the signing key, and makes it possible to forge an administrator cookie. Because failed login attempts never show up on the server, the attack is also hard to detect.
Once in as an administrator, the attacker can run arbitrary server-side JavaScript through the server_code setting. In other words, the path from breaking authentication to executing code was a single straight line.
The role Mythos played
Horizon3 researcher Zach Hanley stresses that Mythos did more than point out the use of weak randomness. It also noticed that the random output leaked through a separate code path and suggested using Z3 to recover the state. In effect, the AI spotted a chain in which two weaknesses only work as an attack when combined. The CVE record reportedly credits Claude and Anthropic Research as collaborators.
According to VulnCheck, which tracks the effort, CVEs tied to Mythos and the related Project Glasswing reached 286 as of October 2. This is reportedly only the second of them to be exploited in the wild. Some reports also say the attacks came from a China-based IP address and US proxy servers, and that servers in the US and Japan were targeted.
What administrators should do now
If you run HFS, the following steps are recommended.
First, find every HFS instance in your organization, whether on a desktop, a server, or in a container. If you are on 3.x, update to 3.2.1 or later. Retire unsupported 2.x versions rather than keep running them. If an instance is exposed to the internet, restrict access with a VPN or firewall rules.
If you were exposing an older version, assume it may have been compromised. Check whether admin settings were changed without your knowledge, and consider rebuilding the environment instead of relying on a patch alone. It is also safest to disable any setting that allows administrator access from localhost.
Summary
An AI found a chain of vulnerabilities, a human researcher verified it, and attackers were using it about a day after the write-up went out. For defenders, it shows that the window between public information and required action keeps shrinking. If you run HFS, update to 3.2.1 or later and review how widely it is exposed, as soon as you can.
