Anthropic's Mythos AI found a critical Rejetto HFS flaw now exploited in the wild
CVE-2026-61500 (CVSS 9.3) in Rejetto HTTP File Server 3.x allows authentication bypass and remote code execution. The flaw was discovered by Anthropic's Mythos model under Project Glasswing, and VulnCheck is already seeing probes against vulnerable servers.
- CVE-2026-61500 has a CVSS score of 9.3 and affects Rejetto HFS 3.x
- Mythos linked the weak xorshift128+ PRNG to leaked values and built an attack chain
- The model used Microsoft's Z3 SMT solver to forge valid session cookies
- VulnCheck detected reconnaissance activity targeting vulnerable systems
Read next
Security