ANTHROPIC Mythos-assisted research has highlighted a critical flaw in Rejetto HFS, tracked as CVE-2026-61500, which is now being exploited in the wild. The vulnerability affects Rejetto HTTP File Server (HFS) 3.x and enables an authentication bypass followed by remote code execution.
Security researchers from Horizon3[.]ai, with support from Anthropic Mythos, demonstrated how an attacker can first enumerate users, then exploit a leakage of values from the same PRNG used to generate the session signing key, forge administrator cookies, and finally achieve arbitrary code execution on the server.
The flaw stems from using V8’s Math[.]random() (xorshift128+), a non-cryptographic PRNG, to seed Koa’s session signing via Keygrip; by observing enough outputs from the same generator, an attacker can reconstruct the internal state and recover the signing key.
Evidence of exploitation has been observed in active reconnaissance campaigns. VulnCheck reported on 2 October that attackers were probing CVE-2026-61500 from a China Telecom IP and targeting canaries in Japan and the United States. The vulnerability affects HFS versions 3.0.0–3.2.0, with a patch released as HFS 3.2.1 on 13 July 2026; Horizon3 notes that previous versions were also vulnerable to multiple security issues.
The practical takeaway is that a weakness once considered difficult to weaponise can now be exploited at scale, aided by AI-assisted vulnerability discovery. Defenders should prioritise upgrading to 3.2.1 and reviewing for compromised admin sessions or similar cookie-forgery indicators.