
A critical vulnerability in Rejetto HTTP File Server, discovered with the help of Anthropic's Mythos AI model, was being actively exploited in the wild within 24 hours of its public disclosure. The incident, tracked as CVE-2026-61500, is the second confirmed case of an AI-found vulnerability being weaponized by attackers — and it's sharpening a debate about whether the traditional disclosure model can survive AI-accelerated discovery.
What happened
On September 30, 2026 (UTC), security researcher Zach Hanley at Horizon3.ai published a write-up detailing CVE-2026-61500, an authentication bypass in Rejetto HFS versions before 3.2.1. The vulnerability stems from a predictable session-signing key derived from JavaScript's Math.random(), which Mythos — Anthropic's specialized cybersecurity model — helped connect to a working exploit chain.
The flaw allows an unauthenticated attacker to forge an administrator session cookie. Once authenticated as admin, the attacker can reach HFS's administrative API, which supports custom endpoints that execute arbitrary JavaScript. That's a direct path from zero access to remote code execution on the server.
HFS is an open-source web file server with roughly 100 internet-facing instances worldwide, according to vulnerability intelligence firms. It previously appeared on the U.S. Cybersecurity and Infrastructure Security Agency's Known Exploited Vulnerabilities catalog in 2024, so it's not an obscure target.
The very next day, October 1, 2026 (UTC), VulnCheck's canary systems detected active exploitation. A China-hosted IP address was targeting vulnerable HFS servers in the United States and Japan. The gap between public disclosure and active exploitation had collapsed to roughly 24 hours.
Why this isn't just another CVE
The technical details of CVE-2026-61500 are serious but not unprecedented. Authentication bypasses leading to RCE are a well-known vulnerability class. What makes this incident different is the timeline and the tooling.
Mythos didn't just flag a suspicious code pattern. It connected a predictable Math.random() signing key to the administrative API's arbitrary JavaScript execution, building a complete exploit chain that a human researcher would typically spend days or weeks constructing. Horizon3's write-up credits Mythos with surfacing the finding and accelerating the analysis.
That acceleration cuts both ways. The same model that helps defenders find and patch vulnerabilities also produces detailed, reproducible exploit write-ups that anyone can read — including attackers. The traditional vulnerability disclosure model assumes a window of days or weeks between public disclosure and widespread exploitation, during which defenders can patch. When AI compresses discovery to hours and the resulting write-up is precise enough to weaponize immediately, that window disappears.
This is the second AI-found vulnerability to be exploited in the wild. The first, earlier in 2026, involved a different software package and a similar timeline. The pattern is clear: AI is shrinking the "danger period" from disclosure to exploitation, and defenders' patch cycles aren't keeping up.
The bigger picture
The cybersecurity industry has spent years building processes around human-speed vulnerability discovery. Coordinated disclosure, 90-day windows, CVE assignment, patch Tuesday — all of these assume that finding a vulnerability and writing a working exploit takes skilled humans weeks of effort. Mythos and similar models break that assumption.
Anthropic has tried to manage this risk through Project Glasswing, which gives Mythos access only to vetted security researchers and critical infrastructure maintainers, and commits $100 million in usage credits to defensive use. But the disclosure itself is public. Once Horizon3 published the write-up, the genie was out of the bottle — and attackers didn't need Mythos to exploit it. They just needed to read the blog post.
The uncomfortable question is whether full-disclosure write-ups remain responsible when AI can turn them into working exploits in hours. Some researchers have begun advocating for more restrained disclosure — technical details shared only with vendors and trusted defenders, with public write-ups delayed until patches are widely deployed. That approach has its own risks: it can leave users in the dark about whether they're affected, and it concentrates vulnerability knowledge in a small group.
What to watch
- Whether CVE-2026-61500 exploitation spreads beyond the initial China-hosted IP to broader ransomware or botnet campaigns
- Whether the 100 internet-facing HFS instances get patched before attackers automate scanning and exploitation at scale
- Whether Horizon3 or other AI-assisted researchers change their disclosure practices in response to the 24-hour exploit window
- Whether CISA or other government agencies issue emergency directives for AI-found vulnerabilities with known active exploitation
- The third, fourth, and fifth AI-found vulnerabilities that get exploited — the point at which this stops being notable and becomes the norm
The vulnerability research community is proud of its full-disclosure tradition, and for good reason: transparency has driven better security for decades. But AI is changing the economics of both offense and defense simultaneously. When a model can find a critical bug and an attacker can weaponize it in the same 24-hour window, the old timeline may no longer protect anyone.
No comments yet