Anthropic's Mythos model has identified a critical authentication-bypass vulnerability in Rejetto HTTP File Server, with exploitation reported within a day of the flaw's Wednesday disclosure.

VulnCheck's canaries detected an attacker in China targeting vulnerable servers in the United States and Japan. The activity indicates that vulnerable HFS deployments were being probed soon after information about the issue became public.

How the vulnerability works

The flaw is tracked as CVE-2026-61500. It involves the way HFS creates the signing key used for Koa session cookies.

That key is derived from Math.random(). The JavaScript engine V8 implements Math.random() through the xorshift128+ algorithm, a detail that Mythos examined while finding the weakness.

The reported issue therefore concerns both authentication and the generation of session-cookie signing material. The supplied reporting does not provide further details about affected versions, available fixes or the attacker's results after targeting the servers.

Why the timing matters

The sequence described in the reporting is notable because detection followed the Wednesday disclosure within a day. VulnCheck observed activity involving servers in two countries, while the attacker was identified as being in China.

The available information identifies the vulnerability as critical and confirms authentication bypass as its impact. It does not establish how many systems were targeted, whether any data was accessed or whether the activity led to successful compromise.

Conclusion

Mythos found a critical authentication-bypass flaw in Rejetto HTTP File Server, and VulnCheck detected targeting of vulnerable servers in the United States and Japan within a day of disclosure.

Frequently Asked Questions

Q. What product is affected?

The affected product is Rejetto HTTP File Server.

Q. What is the vulnerability identifier?

The flaw is tracked as CVE-2026-61500.

Q. What kind of weakness was found?

It is described as a critical authentication-bypass vulnerability.

Q. Which model found the flaw?

Anthropic's Mythos model identified the vulnerability.

Q. Where were the targeted servers located?

VulnCheck detected targeting of vulnerable servers in the United States and Japan.

Q. What technical component is involved?

The issue concerns the signing key for Koa session cookies and its derivation from Math.random().