Back to News
SecurityAI Understanding briefing

Exploitation of Rejetto HFS vulnerability discovered by Anthropic’s Mythos AI raises security concerns

SecurityWeek reports that threat actors are actively exploiting CVE‑2026‑61500 in Rejetto HTTP File Server, a flaw originally uncovered by Anthropic’s Mythos AI model, to forge admin cookies and achieve remote code execution.

4 min readRead the linked source
Source-provided image accompanying Exploitation of Rejetto HFS vulnerability discovered by Anthropic’s Mythos AI raises security concerns
Source referenceSource recorded
Publisher
securityweek.com
Source link
securityweek.comhttps://www.securityweek.com/exploitation-hits-rejetto-hfs-vulnerability-discovered-by-ai/
Source type
Linked source — primary-source status has not been established.
ContextUnderstand this in 60 seconds

Start here

Key terms

Algorithm
A defined set of rules or steps that a computer follows to solve a problem or complete a task.
Feature
An input variable used by a model to make predictions.
Prompt
The input instructions and context provided to a generative model.
Test yourselfAI Security Quiz

What happened

Threat actors are exploiting a critical vulnerability (CVE‑2026‑61500, CVSS 9.3) in the open‑source Rejetto HTTP File Server (HFS). The flaw allows unauthenticated users to reconstruct the session‑cookie signing key by observing outputs of the server’s Math.random() generator, which uses the reversible xorshift128+ . With the recovered key, attackers can forge administrator cookies and execute arbitrary code via the server_code configuration. Horizon3.ai disclosed that its researchers discovered the flaw using Anthropic’s Mythos AI model, which identified the reversibility of the PRNG. Rejetto released version 3.2.1 on July 13 with patches. On October 2, VulnCheck warned that exploitation attempts have begun, originating from a China Telecom IP and targeting canaries in Japan and the United States.

The vulnerability stems from Rejetto HFS exposing outputs of its non‑cryptographic session‑cookie generator to unauthenticated clients during login. The generator, based on the xorshift128+ , produces values that can be reversed, allowing an attacker who collects a few login responses to reconstruct the generator’s internal state.

Horizon3.ai’s technical report explains that once the session‑cookie signing key is recovered, an attacker can forge valid administrator cookies. These forged cookies grant elevated privileges, enabling remote code execution through the server_code configuration option.

Anthropic’s Mythos AI model was used by Horizon3.ai to recognize the reversibility of the PRNG and to formulate the attack path. The AI’s mathematical reasoning accelerated the discovery of the flaw, which was reported to Rejetto in June.

Rejetto responded with a patched release (v3.2.1) on July 13. However, VulnCheck’s October 2 advisory indicates that exploitation attempts have already begun, targeting canary systems in Japan and the United States from a China Telecom IP address.

The report does not provide independent verification of successful compromises beyond the observed reconnaissance activity, and no public exploit code has been released.

Source details: securityweek.com ↗

Why it matters

The incident illustrates how AI‑assisted vulnerability discovery can accelerate both defensive and offensive security activities. By leveraging advanced mathematical reasoning, Mythos identified a subtle weakness in a widely deployed file‑server product, prompting a rapid patch. However, the same AI‑derived insight appears to have been weaponized by attackers within weeks, exposing servers that have not yet applied the update. Given the high CVSS score and the ease of forging admin cookies, unpatched HFS installations face a severe risk of remote code execution, potentially leading to data theft, ransomware deployment, or lateral movement within networks. The case also underscores the broader challenge of securing software that relies on weak random number generators, especially when those weaknesses become more visible through AI analysis.

AI‑driven vulnerability discovery can shorten the time between flaw identification and patch release, improving overall software security. Conversely, the same AI insights can be rapidly adopted by malicious actors, compressing the window for defenders.

The use of a reversible PRNG for session‑cookie signing violates best practices for cryptographic randomness, highlighting a class of weaknesses that may exist in other legacy or open‑source projects.

Given the high severity rating (CVSS 9.3) and the ease of forging admin credentials, any unpatched HFS deployment is at immediate risk of remote code execution, which could be leveraged for data exfiltration, ransomware, or as a foothold for deeper network intrusion.

The incident may broader scrutiny of random number generation practices in web servers and other networked applications, potentially leading to new security guidelines or mandatory updates.

Interactive Mechanism

Interactive Mechanism: How It Actually Works

Explore the underlying technology behind this development interactively.

Thinking Budget (Test-Time Tokens):1,024 tokens
Complex Accuracy79%Math & Code Logic
Latency3.2sTime to first full output
Inference Cost$0.0092Per query estimated
Reasoning StyleStep VerificationInternal chain depth
Active Thinking Trace:
1Deconstruct user problem into formal constraints
2Propose candidate hypotheses & step-by-step calculation
3Self-correction: Backtrack and refute subtle edge cases
4Exhaustive consistency check & final output synthesis
Core takeaway: Test-time compute fundamentally changes AI economics. Instead of only scaling during pre-training, giving reasoning models more tokens at inference time allows them to systematically solve PhD-level STEM problems.
Interactive Concept Check+10 Points
AI Security Quiz

A public chatbot and an internal agent with write access are being assessed. Why need separate threat models?

What to watch next

Security teams should monitor for indicators of compromise linked to forged HFS admin cookies, such as unexpected processes spawned by the server_code or anomalous traffic from known malicious IP ranges. Organizations using Rejetto HFS must verify that version 3.2.1 or later is deployed and consider additional network segmentation to limit exposure. Researchers will likely examine whether other software that employs Math.random() or similar PRNGs is vulnerable to similar reconstruction attacks, potentially prompting broader advisories. Finally, the security community will watch how AI tools are employed in both vulnerability research and exploitation, influencing future threat‑modeling and defensive strategies.

Detection of forged HFS admin cookies in network logs or authentication systems.

Unusual execution of scripts or commands via the server_code configuration on HFS instances.

Emergence of similar PRNG‑related vulnerabilities in other software, especially those using Math.random() or xorshift algorithms.

Further disclosures from security firms about AI‑assisted discovery techniques and their impact on threat landscapes.

Responses from Rejetto regarding additional mitigations, such as deprecating the vulnerable PRNG or providing migration tools for existing installations.

Related guides & quizzes

AI SecurityAI Models ExplainedAI EthicsFuture of AITest what you know — try a free AI quizLook up an AI term in our glossaryFollow the AI regulation tracker
Found this useful?