Anthropic & Claude

CVE-2026-61500: Mythos Found the Rejetto HFS Flaw, and a Day Later It Was Under Attack

2 min read AI-generated

Project Glasswing has turned up 286 CVEs so far. Exactly two of them have since been attacked in the wild.

Featured image for "CVE-2026-61500: Mythos Found the Rejetto HFS Flaw, and a Day Later It Was Under Attack"

Zach Hanley at Horizon3 used Claude Mythos on Wednesday to turn up a critical flaw in the Rejetto HTTP File Server. CVE-2026-61500: an authentication bypass that hands over admin access and, with it, remote code execution. The fix is in version 3.2.1 and later. By Thursday evening, one day after disclosure, the first attack was running.

The report rests on a single investigation by The Register; Jessica Lyons pulled together the exploitation data from VulnCheck and the technical analysis from Horizon3.

xorshift128+, an SMT solver and a session token

The interesting part is what the flaw actually was. HFS generates its session tokens with the xorshift128+ pseudorandom generator. Mythos showed that the generator’s internal state can be recovered from observed values if you point the Z3 SMT solver at it, and that valid sessions can then be predicted.

This is not a flaw you notice while reading the code. You notice it when somebody writes down a system of equations and solves it. That is precisely what Anthropic built Mythos for, and precisely why the line produces a different class of finding in security work than a linter does.

The first attack came a day after disclosure

The timeline is the real story. Found on Wednesday, first attempts Thursday evening — from a China-hosted IP, aimed at vulnerable servers in the US and Japan. By Friday four more hits had landed, through two US proxy IPs. The numbers come from Patrick Garrity at VulnCheck.

One day is the entire window administrators got here. If you didn’t patch on Thursday, Thursday evening was your turn.

286 findings, two attacks

Project Glasswing, Anthropic’s vulnerability-hunting program, stood at 286 CVEs found as of Friday. Horizon3 joined in July. Of those 286, exactly one other has actually been attacked. CVE-2026-61500 makes two.

That ratio strikes me as more remarkable than the 286. It means the program mostly finds things nobody else had found, and the patch beat the first attacker almost every time. Twice it didn’t.

It also shows the other face of the same capability. When GLM-5.3 wrote exploits at the level of Claude Mythos Preview but without the safeguards, that was the uncomfortable version. Here the same capability works the defensive side, and since Mythos 5 opened up for cyber defense the hit count has kept climbing. The gap between finding and attack is shrinking on both sides — that is the number I’ll be watching over the next few months.

Sources:

AnthropicClaude MythosSicherheitProject GlasswingCVE