Anthropic's Mythos AI found a critical Rejetto HFS flaw now under active exploitation
Anthropic's bug-hunting model Mythos uncovered CVE-2026-61500, a critical authentication-bypass flaw in the open-source Rejetto HTTP File Server that allows full admin access and remote code execution. VulnCheck detected exploitation attempts the next day from a China-based IP targeting hosts in the US and Japan. The fix is available in HFS v3.2.1 or later.
- CVE-2026-61500 is an auth bypass in Rejetto HFS leading to RCE
- The flaw was found by Anthropic's Mythos under Project Glasswing
- Exploitation came from a China-based IP against US and Japan hosts
- The fix ships in HFS v3.2.1 and later
Read next
Security