VYPR
researchPublished Oct 3, 2026· 1 source

Anthropic's AI Model Mythos Uncovers Critical Rejetto HFS Authentication Bypass

Anthropic's AI model Mythos has been instrumental in discovering CVE-2026-61500, a critical authentication bypass vulnerability in Rejetto HTTP File Server (HFS) that allows for remote code execution and administrative access.

Anthropic's advanced AI model, Mythos, has once again demonstrated its prowess in cybersecurity by aiding in the discovery of a critical vulnerability in Rejetto HTTP File Server (HFS). The flaw, now designated CVE-2026-61500, represents a significant authentication bypass that can grant attackers full administrative control and enable remote code execution on affected systems. This marks the second instance where a vulnerability identified with Anthropic's AI assistance has seen exploitation in the wild.

The vulnerability was uncovered by Zach Hanley, a researcher at the AI pen-testing firm Horizon3. Hanley utilized Mythos, part of Anthropic's Project Glasswing initiative which provides select partners with access to its powerful bug-hunting AI, to analyze the HFS software. The findings revealed a critical security weakness that has since been patched by the vendor in version 3.2.1 and later. Hanley also released a demonstration video showcasing the exploit chain, which allows for remote code execution on a compromised server.

Exploitation of CVE-2026-61500 began shortly after its disclosure. Security researchers at VulnCheck observed initial malicious activity originating from an IP address in China, targeting vulnerable HFS instances located in the United States and Japan. This early exploitation highlights the rapid pace at which vulnerabilities, especially those with significant impact, are weaponized by threat actors.

Mythos's capability in uncovering this specific vulnerability stems from its advanced mathematical and scientific analysis skills. The flaw lies within the V8 JavaScript engine's Math.random() function, which HFS uses for authentication. Mythos identified that the pseudo-random number generator (PRNG) employed by V8's implementation was not cryptographically secure and, crucially, was reversible. This reversibility, combined with the application leaking the Math.random() outputs, allowed attackers to derive the signing key for session cookies.

According to Hanley, Mythos's analysis went beyond simply flagging an insecure PRNG. The AI model simultaneously recognized that the application leaked the necessary Math.random() outputs through a separate code path. It then determined that these combined factors provided sufficient information to recover the PRNG's state, enabling the forging of valid session cookies and thus bypassing authentication.

This discovery is particularly noteworthy as it involved the use of a Satisfiability Modulo Theories (SMT) solver, Z3, to recover the PRNG seed. While SMT solvers are powerful tools in formal verification and security research, their application in directly attacking a cryptographic flaw within a live application to bypass authentication is a novel approach, further underscoring Mythos's analytical depth.

Rejetto HFS has a history of security issues, having previously been listed on the US Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities (KEV) catalog in 2024. The addition of CVE-2026-61500 underscores the ongoing need for users of this software to maintain up-to-date installations and remain vigilant against emerging threats.

Anthropic has notably kept Mythos largely private, citing its immense power and potential for misuse. Project Glasswing, which granted Horizon3 access, is part of this controlled release strategy. As of the time of reporting, Mythos and Project Glasswing have been credited with discovering 286 CVEs, with CVE-2026-61500 being one of the few to have been actively exploited in the wild, demonstrating the real-world impact of AI-driven vulnerability research.

Synthesized by Vypr AI