A critical authentication-bypass vulnerability in Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500, was exploited in the wild within a day of it being made public. The flaw allows full admin access and remote code execution. Users are urged to update to HFS v3.2.1 or later. VulnCheck researcher Patrick Garrity said initial activity came from an IP address in China targeting hosts in the US and Japan, while later hits appeared to originate from two US IPs that were likely proxies.

The bug was uncovered by Anthropic's Mythos model, which the company has kept out of general release. According to Horizon3 researcher Zach Hanley, Mythos discovered that HFS uses V8's Math.random() — based on the reversible xorshift128+ algorithm — to generate a session signing key, and that the application leaks raw Math.random() outputs through a separate code path. Mythos then used Microsoft's Z3 solver to recover the PRNG seed and forge valid session cookies, bypassing authentication. Hanley said his team had not previously seen an SMT solver used this way against a real-world cryptographic flaw.

Mythos and Anthropic's Project Glasswing have now produced 286 CVEs, according to Garrity's tracker, but only two have been exploited in the wild. The Rejetto case highlights the model's strength in mathematical reasoning and its ability to chain separate weaknesses into an exploitable route. This article is based on a single report from The Register; no other sources were available for comparison.