Probes hit Mythos-found Rejetto HFS bug as Anthropic opens tiers
Attackers are probing Rejetto HFS flaw CVE-2026-61500, found with Anthropic’s Mythos, while Anthropic opens three vetted Claude cyber tiers.
Horizon3.ai’s Zach Hanley used Anthropic’s Mythos model through Project Glasswing to find CVE-2026-61500, a CVSS 9.3 authentication-bypass in Rejetto HTTP File Server 3.0.0 through 3.2.0—Security Affairs says 3.x—that can yield forged administrator cookies and remote code execution. Reports say the session-cookie signing key comes from non-cryptographic Math.random() (V8 xorshift128+, described as a Koa key) and that login responses leak generator output; discovery is placed in June, publication was through the VulnCheck CNA, the fix shipped in 3.2.1 on July 13, 2026, BleepingComputer lists 3.3.4 as the latest stable release, and a public proof of concept appeared in late September (September 30). Exploitation reporting disagrees: The Hacker News describes October 1 attempts by a China-based actor against US hosts, and The Register describes a China-hosted IP hitting real hosts in the US and Japan plus four later hits from two apparent US proxy addresses, while SecurityWeek’s October 2 account and BleepingComputer describe small-scale reconnaissance from a single China Telecom IP against canaries or honeypots in Japan and the United States, and BleepingComputer says no successful exploitation is confirmed. On October 6 Anthropic merged its Cyber Verification Program and Project Glasswing into Defense, Red Team, and Specialized Access tiers covering Claude Opus 5.5, Sonnet 5.5, and Mythos 5.1—Security Affairs also names Fable 5.1—on the Claude Platform, Vertex AI, and Microsoft Foundry, with fewer safeguards, organization-only Red Team access, continued blocks on ransomware, physical harm, and widespread disruption, and US-government review for specialized testing of power grids and interbank or payment networks. Glasswing partners reported at least 129,000 verified vulnerabilities from April to July 2026, more than 33,000 critical or high, plus 5,500 from open-source scanning; VulnCheck said only CVE-2026-26980 in Ghost CMS and CVE-2026-61500 were exploited in a 300-flaw sample, separate from Garrity’s 286 Mythos/Glasswing CVEs with two known exploited. On CyScenarioBench, sources agree that access outside the program blocked all 50 Opus 5.5 trials and that Red Team access completed 34 of 50 and blocked none, while Defense Access blocked 46 of 50 and GBHackers says it completed 4; The Hacker News also cited Veracode’s claim that about 44% of AI code tasks introduced a vulnerability, and older HFS flaw CVE-2024-23692 remains in CISA’s KEV catalog.
- CVE-2026-61500 (CVSS 9.3) is an authentication-bypass in Rejetto HTTP File Server 3.0.0 through 3.2.0 (Security Affairs says 3.x), fixed in 3.2.1 on July 13, 2026; BleepingComputer lists 3.3.4 as the latest stable release.
Coverage timelineoldest first · each row is one article
- · 5d agoAnthropic's super bug-hunting model Mythos is hardcore good at math, as latest vuln under attack shows
The Register · Security· 74
Attackers are exploiting CVE-2026-61500, a critical Rejetto HFS auth bypass discovered by Anthropic’s Mythos.
- · 3d agoAttackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE
The Hacker News· 78
Attackers are exploiting Rejetto HFS CVE-2026-61500 to forge admin sessions and gain remote code execution.
- · 3d agoExploitation Hits Rejetto HFS Vulnerability Discovered by AI
SecurityWeek· 76
Vulnerabilities in this storyAll →
- CVE-2024-236929.899%Unauthenticated Template Injection RCE in Rejetto HTTP File Server 2.3mpublished · rejetto HTTP File Server KEV ransomware PoC ×5