Rejetto HFS CVE-2026-61500, Found With Anthropic's Mythos, Was Probed One Day After Disclosure
Security / news
Rejetto HFS CVE-2026-61500, Found With Anthropic's Mythos, Was Probed One Day After Disclosure
A predictable session-signing key lets an unauthenticated attacker forge an HFS admin cookie and run server-side JavaScript; HFS 3.2.1 has carried the fix since July.
An unauthenticated attacker who can reach a Rejetto HFS 3.0.0 through 3.2.0 server can forge an administrator session cookie and then run JavaScript on the host through the server_code setting. The flaw, CVE-2026-61500 (CVSS 9.3), has been fixed since HFS 3.2.1 in July 2026, and attackers began probing for it on Oct. 1, a day after Horizon3 published its write-up.
The practical instruction is to upgrade. BleepingComputer recommends 3.2.1 at minimum and, ideally, the latest stable release, 3.3.4.
What the bug is and why it falls out of two small mistakes
HFS derives its session-cookie signing key from Math.random(). The Register explains that HFS hands that value to Koa, which uses keygrip to sign session cookies, and that V8's Math.random() is built on xorshift128+, a generator that is not cryptographically secure and whose output can be reversed. The second mistake is a separate code path that leaks raw Math.random() outputs to unauthenticated clients during login.
Together those let an attacker collect a small number of login responses, reconstruct the generator's state, recover the signing key and sign a valid administrator cookie. The Hacker News quotes the advisory: HFS "derives its session-cookie signing key from the non-cryptographic Math.random() generator."
The score reads correctly here. It needs no credentials and no user interaction, and the end state is code execution as whatever account runs HFS. BleepingComputer lists reaching internal systems from the compromised host among the possible outcomes.
Horizon3 says Anthropic's Mythos found it
Zach Hanley of Horizon3, which sells AI-driven penetration testing, published the write-up and an exploitation video on Wednesday, Sept. 30. He said Anthropic's Mythos model located the weak key generation and the separate leak, then linked them. The Register reports that the model's analysis proposed using Z3, Microsoft's SMT solver, to recover the generator's seed, and that Hanley's team could not recall an SMT solver being used this way against a cryptographic flaw in a real application.
Every account of the Mythos role comes back to Horizon3's own statement. None of the pages fetched for this report carries independent verification, so the Mythos claim is Horizon3's own.
The sources disagree on sequence. The Register says Hanley's team reported the bug to VulnCheck for CVE assignment, while BleepingComputer dates the CVE's first appearance on the NVD to July 13, 2026. The Hacker News adds that The Hacker News says a Python proof of concept by Alejandro Ramos (aramosf) circulated in late September, about three months after the patch.
| Date | Event |
|---|---|
| July 13, 2026 | CVE on NVD, per BleepingComputer; HFS 3.2.1 released in July |
| Sept. 30, 2026 | Horizon3 publishes write-up and exploit video |
| Oct. 1, 2026 | VulnCheck sees first exploitation attempts |
| Oct. 2, 2026 | Four hits from two US addresses, per The Register |
Who is probing, and how much of it there is
Patrick Garrity of VulnCheck said exploitation attempts began on Thursday, Oct. 1. Caitlin Condon, VulnCheck's vice president of security research, called the activity "small-scale reconnaissance only": one China Telecom address probing VulnCheck's Canary honeypots in Japan and the United States. On Friday Garrity reported four hits from 173.239.211.248 and 173.239.211.249, which he said appeared to come from a proxy.
Nothing in the three sources reports a confirmed compromise, an exposed-server count or a statement from Rejetto. VulnCheck lists the CVE in its own exploited catalog. The sources do not say whether CISA has added it, though HFS appeared there in 2024 for an earlier flaw, CVE-2024-23692.
That earlier flaw (CVSS 9.8) was used in July 2024 to deliver cryptominers, trojans and the HATVIBE malware, according to The Hacker News. Related zero-day reporting on this site includes Fortinet's FortiMail flaw and F5's BIG-IP APM bug.
Mythos and the exploitation tally
Garrity's tracker lists 286 CVEs credited to Mythos and Project Glasswing as of Friday, per The Register, which calls this the second Anthropic-linked vulnerability known to be exploited in the wild. Exploitation within a day of a public write-up is the pattern; the number to watch is whether VulnCheck's hit count moves past four.
Sources
More in Security
- 01CISA Gave Agencies Three Days for Five 2015-2023 Bugs, and Four Come With a Forensic Triage OrderThe October 8 additions to the exploited-vulnerabilities catalogue show how BOD 26-04 has changed what a deadline means: the patch is the smaller job.
- 02Apple's CoreGraphics Zero-Day CVE-2026-86950 Has a CISA Deadline of October 13, Not the October 2 Being ReportedTrade coverage gives a three-day federal deadline. The catalogue entry itself carries 14 days and no forensic-triage flag.
- 03Exchange CVE-2026-96940 Lets Any Mailbox User Read Others' Mail, and Patched Servers Need V2Microsoft's out-of-band September V2 update closes an 8.8-rated authorization flaw in on-premises Exchange, with four KBs and a support cliff for 2016 and 2019.
- 04Citrix's Third NetScaler Zero-Day in Seven Days Crashes Appliances Already PatchedCVE-2026-88779 hits SAML-configured NetScaler boxes that had just taken the Sept. 27 fixes, and attackers were already trying to drop a payload through it.