Rejetto HFS vulnerability found by Mythos is under attack
A Rejetto HFS vulnerability found with Anthropic's Mythos, CVE-2026-61500, was attacked a day after its write-up. How it works and why 3.2.1 fixes it.
Source-based. Written from the documents, reporting and reviews linked in the text. Nothing here was tested hands-on by The Ruling Desk. How we work

Attackers started probing a critical Rejetto HFS vulnerability, CVE-2026-61500, one day after security firm Horizon3 published how it works, and the bug was found with Anthropic's Mythos model. HFS versions 3.0.0 through 3.2.0 let an outsider forge an administrator login and then run code on the server. The fix, HFS 3.2.1, has been out since July 13, 2026, so anyone still on an older 3.x build should update now.
Key takeaways
- What it is: HFS signed its login cookies with a key built from
Math.random(), a generator that isn't meant for secrets, and leaked that generator's output to anyone who started a login, Horizon3 says. - How bad: GitHub's advisory rates it 9.3 out of 10 (critical, CVSS 4.0). No password is needed, and a forged admin session leads to code execution.
- Attacked within a day: VulnCheck says its decoy servers saw exploitation attempts on October 1, the day after Horizon3's September 30 write-up.
- The fix is old: HFS 3.2.1 shipped on July 13. If you updated since then, you are not exposed to this bug.
- The AI angle, by the numbers: a VulnCheck tracker counts 286 CVEs linked to Anthropic or Project Glasswing, and this is only the second one known to be exploited.
How the Rejetto HFS vulnerability works
HFS is a small web file server that turns a computer into a place to share folders over HTTP, and it runs on Windows, Linux, macOS, FreeBSD and Android. Version 3 is a TypeScript rewrite of the older Windows program.
According to Horizon3's write-up by researcher Zach Hanley, the attack chains three weaknesses:
- A guessable signing key. HFS 3.x generated the secret that signs session cookies with
Math.random(). In Node.js, that function runs on V8's xorshift128+ algorithm, which is fast but not cryptographic: its internal state can be worked out from its output. - A leak of that output. A login step called
loginSrp1handed rawMath.random()values to unauthenticated clients. Horizon3 says 3 to 5 consecutive values are enough. - A solver to finish the job. Feeding those values to Z3, Microsoft's equation solver, recovers the generator's state. Stepping it backwards rebuilds the key HFS created at startup.
With the key, an attacker signs their own admin cookie. Horizon3's version also sets a session flag that skips HFS's check that a session stays on one IP address. The GitHub advisory says an admin can then run code through HFS's server_code setting, which means full control of the machine HFS runs on. The attacker does need a valid admin username, and Horizon3 says it reported a separate user enumeration bug that helps find one.

What Mythos did, and what it didn't
Hanley used Mythos through Project Glasswing, Anthropic's limited program that gives vetted defenders access to the model. Horizon3 joined it in July, The Register reports.
Weak random numbers are a well-known class of bug. What Hanley highlights is the chaining: quoted by The Register, he says Mythos spotted the weak generator and the separate leak, and "recognized those two facts as a chain." Horizon3 also says the model proposed the seed-recovery attack on its own, without follow-up prompts. That is Horizon3's account of its own session; nobody has published a controlled comparison with other tools.
The HFS 3.2.1 release notes say multiple flaws in all earlier versions could give an attacker admin access, and credit Hanley working with Claude and Anthropic Research. For more on how these models perform at attack work, see our coverage of GLM-5.3's exploit tests.
Attacks began a day after the write-up
VulnCheck researcher Patrick Garrity said its canaries, decoy servers built to attract attacks, caught exploitation of CVE-2026-61500 on the evening of Thursday, October 1. The Register reports the first traffic came from a China-hosted IP address aimed at hosts in the US and Japan, followed on Friday by four more hits from two US addresses that appeared to sit behind proxies. SecurityWeek describes it as small-scale reconnaissance from a China Telecom address.
Attackers didn't have to build much themselves. The Hacker News reports that researcher Alejandro Ramos published a proof of concept in late September. VulnCheck lists the bug in its own known exploited vulnerabilities catalog, according to its advisory.
| Date (2026) | What happened |
|---|---|
| July 13 | HFS 3.2.1 released with the fix; GitHub advisory published |
| September 30 | Horizon3 publishes its technical write-up |
| Late September | A public proof of concept appears, per The Hacker News |
| October 1 | VulnCheck sees the first exploitation attempts |
| October 2 | More hits from two US IP addresses, per The Register |
HFS has been a target before. The Hacker News notes that attackers used an earlier flaw, CVE-2024-23692, in 2024 to drop cryptocurrency miners and trojans.
Why it matters if you run HFS
HFS is built for sharing files straight from your own computer, and sharing beyond your home network means putting it on the internet. That is the setup this bug punishes: no password needed, a public exploit and active scanning.
Of the 286 Anthropic- and Glasswing-linked CVEs in Garrity's tracker as of October 2, only two are known to be exploited, The Register reports. The first was a SQL injection bug in Ghost, CVE-2026-26980, which The Register covered on September 21. AI finding bugs faster doesn't mean attackers use most of them. It does mean a detailed public write-up can turn into attacks within a day. For another bug under attack this week, see the NetScaler SAML zero-day.
What to do now
- Check your version in the HFS admin panel. Anything from 3.0.0 to 3.2.0 is vulnerable.
- Update to 3.2.1 or later from the official releases page or with the panel's "check for updates" option.
- If an unpatched server faced the internet, we'd treat it as possibly compromised: review admin accounts, any custom server code in the configuration, and files you didn't put there.
- Keep the admin panel off the open internet unless you really need it there.
Bottom line
This Rejetto HFS vulnerability, CVE-2026-61500, is a critical, password-free path to taking over HFS 3.0.0 through 3.2.0. Horizon3 found it with Anthropic's Mythos, the fix has been available since July 13, and VulnCheck saw attacks start a day after the details went public. If you run HFS, confirm you're on 3.2.1 or later today. For the wider picture of AI models in security work, see our explainer on AI security incidents at OpenAI and Anthropic.
FAQ
Which HFS versions are affected by CVE-2026-61500?
HFS 3.0.0 through 3.2.0, according to the GitHub advisory. Version 3.2.1, released July 13, 2026, fixes it, and later versions include the fix.
Is CVE-2026-61500 being exploited?
Yes. VulnCheck reported exploitation attempts against its decoy servers starting October 1, 2026, and VulnCheck lists it as known exploited. The activity reported so far is small in scale.
Did an AI find the bug on its own?
Horizon3's Zach Hanley found it using Anthropic's Mythos model. Horizon3 says the model identified the weak generator, the leak and the way to recover the key without follow-up prompting, but a researcher ran the work and the disclosure.