WORLDTECH NEWS Global technology intelligence.Contact
← Back to WORLDTECH
Cybersecurity SINGLE SOURCE

Anthropic Mythos Found A Bug in Rejetto HFS. Attackers Are Now Exploiting It.

Two analysts silhouetted in front of monitors in a security operations centerAI illustration
WORLDTECH illustration · AI-generated (Canva)

What happened

AI-assisted research uncovered a critical Rejetto HFS flaw that enables authentication bypass and remote code execution (running programs on a machine from somewhere else), now exploited in the wild. A Rejetto HFS vulnerability, tracked as CVE-2026-61500 (CVSS score of 9.3), discovered with the help of the Anthropic Mythos AI model is now being exploited in the wild, turning an interesting security research experiment into a much more practical warning for defenders. Anthropic is an artificial intelligence company based in San Francisco, and its products and services include Claude Code.

Attackers can exploit it to bypass authentication, obtain administrative access and ultimately execute arbitrary code on the server. VulnCheck observed reconnaissance activity targeting vulnerable systems.

“Earlier today, VulnCheck ‘s Canary Intelligence network started detecting probes for CVE-2026-61500, a session-forgery-via-weak-signing-key vulnerability in Rejetto HFS, an open-source file server.” The vulnerability affects Rejetto HTTP File Server (HFS) 3.x.

Sources & evidence