A critical authentication-bypass vulnerability in Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500, has been discovered and is now under active exploitation. Based on information from The Register, this flaw allows for full administrative access and remote code execution on vulnerable systems.
The vulnerability, initially exploited from an IP address in China targeting hosts in the US and Japan, was uncovered by researcher Zach Hanley of Horizon3. The flaw stems from an insecure pseudo-random number generator used by HFS, which, combined with a leak of the generator's output, allowed attackers to forge session cookies and gain administrative control. This discovery was facilitated by Anthropic's AI model, Mythos, which is part of its Project Glasswing initiative.
Mythos demonstrated a sophisticated ability to link mathematical concepts, cryptographic missteps, and code leaks to identify the exploit. The Rejetto HFS software has been updated to version 3.2.1 to address this and other security flaws. This incident highlights the growing capability of AI models in uncovering complex security vulnerabilities and the subsequent rapid exploitation by malicious actors, with initial attacks originating from China and later from US-based proxies.
Source: The Register
