Attackers probe a Rejetto HFS flaw that reports tie to Anthropic's Mythos model
CVE-2026-61500 lets attackers forge admin sessions on file servers running versions 3.0.0 through 3.2.0. A fix has been available since July.

Evidence: Official disclosure. Security stories run only with a named disclosure or independent reporting behind them.
Attackers are targeting CVE-2026-61500, a critical flaw in Rejetto HTTP File Server, a free, open-source tool for self-hosted file sharing. BleepingComputer cites the NIST description: versions 3.0.0 through 3.2.0 derive the session-cookie signing key from the non-cryptographic Math.random() generator and leak outputs of that same generator to unauthenticated clients during login. By collecting a few login responses, an attacker can reconstruct the generator's state, forge an administrator cookie, and achieve remote code execution through the server_code configuration feature. The flaw was first published on July 13 and is fixed in version 3.2.1. VulnCheck's Caitlin Condon said the company's honeypots observed probes, which she described as small-scale reconnaissance from a single China Telecom IP address against deployments in Japan and the US. Tech Times and Security Affairs report that the bug was uncovered by Anthropic's restricted Mythos model using a formal-methods reasoning tool. Tech Times calls it only the second confirmed in-the-wild exploitation of a vulnerability found through Project Glasswing. BleepingComputer credits the discovery to Horizon3 researchers. Operators of affected versions are advised to update.