Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.
Anthropic published updated Project Glasswing data on October 2, 2026, disclosing 6,157 vulnerabilities across 591 open-source projects. The same day, Horizon3's Zach Hanley confirmed that CVE-2026-61500 — an authentication bypass in Rejetto HFS discovered via the Mythos model — was actively exploited in the wild within 24 hours of disclosure, with initial attempts from a Chinese IP against hosts in the United States and Japan. The combination of exploitation speed and the flaw's technical sophistication signals a qualitative shift in vulnerability research: AI models are now producing attack chains built on cryptographic primitives that exceed conventional human penetration testing capabilities.
- The Mythos model identified CVE-2026-61500 in Rejetto HFS by exploiting the reversibility of the xorshift128+ PRNG through the Z3 SMT solver, a technique traditionally associated with academic research.
- The vulnerability, rated CVSS 9.8 CRITICAL in the official record, enables authentication bypass and remote code execution.
- VulnCheck's Garrity detected active exploitation the day of disclosure, with canary hosts in the US and Japan hit by an actor with infrastructure in China.
- Project Glasswing has produced 6,157 vulnerabilities with a 92.7% true positive rate, but only 516 have been patched out of 584 advisories issued.
How Mythos Broke Authentication with a Mathematical Solver
The vulnerability chain identified by Mythos unfolds in three interconnected phases, each of which would have escaped superficial analysis. The model determined that Rejetto HFS's JavaScript implementation used Math.random(), whose underlying engine — xorshift128+ — is deterministic and fully reversible. This finding in isolation would not constitute an exploitable vulnerability: the PRNG must be predictable and its output must be exposed to the attacker.
Mythos simultaneously identified that the application leaked raw Math.random() output through a separate code path, and recognized that the combination of these two facts made internal generator state recovery feasible. To resolve the mathematical constraints, Hanley applied Z3, an SMT solver developed by Microsoft Research, to invert the PRNG's transition function and forge valid authenticated sessions. Horizon3 had not previously observed an SMT solver employed in this manner against a real-world application to bypass authentication.
"Mythos didn't just flag the insecure PRNG in isolation – it simultaneously identified that the application leaked raw Math.random() outputs through a separate code path, recognized those two facts as a chain, and determined the leak produced exactly the observations needed to make state recovery feasible" — Zach Hanley, Horizon3
The Timeline: From Disclosure to In-the-Wild Exploitation
The speed of the discovery-to-exploitation cycle is the most unsettling aspect of the incident. Hanley published CVE-2026-61500 details on Wednesday, October 1. On Thursday, October 2, VulnCheck's Patrick Garrity reported: "We started detecting exploitation of CVE-2026-61500 in Rejetto HFS this evening." VulnCheck canaries recorded attacks from a Chinese IP against real vulnerable hosts in the United States.
On Friday, October 3, Garrity reported four additional hits from two US IPs belonging to the same subnet, exhibiting technical proxy characteristics. The source does not specify whether these attempts trace back to the initial actor or a distinct operator. What is documented is that the first in-the-wild exploit occurred within a timeframe that precludes systematic patching: the exposure window was compressed to a single day.
The Project Glasswing Context
The official Anthropic dashboard, updated October 2, 2026, quantifies the program's scope: 6,157 vulnerabilities disclosed across 591 open-source projects, with 516 patches released by maintainers and 584 advisories issued (219 CVEs and 365 GHSAs). Human triage confirmed the validity of 5,674 findings out of 6,123 reviewed, for a 92.7% true positive rate.
According to Garrity's tracker, Mythos had accumulated 286 attributed CVEs as of October 3, 2026. CVE-2026-61500 is the second of these CVEs to be actively exploited in the wild. Anthropic's official source does not explicitly link the individual identifier to the Mythos model in the aggregated dashboard; the connection is established by The Register's reporting and Hanley's statements.
Rejetto HFS is notoriously vulnerable: the CISA KEV catalog lists previous vulnerabilities in the product, though it does not mention CVE-2026-61500. The historical presence in the federal catalog indicates the target was already monitored, but not that the specific flaw was known prior to disclosure.
Immediate Actions
The source documents the following priority actions:
- Update Rejetto HFS to version 3.2.1 or later, which fixes the vulnerability per The Register's reporting.
- Monitor authentication logs for anomalous sessions that could stem from PRNG forgery, given the documented attack technique. \li>Assess the presence of Rejetto HFS in internet-exposed assets, considering the software already appears in the CISA KEV with previous vulnerabilities.\li>Track the Mythos/Project Glasswing CVE tracker to identify any other flaws in your tech stack that may have been disclosed in the same batch.
Why the Method Matters More Than the Single CVE
The relevant technical datum is not the severity of CVE-2026-61500, but the class of vulnerability Mythos managed to extract. The use of the Z3 SMT solver to invert xorshift128+ represents a qualitative leap over hunting for known patterns or conventional static analysis: the model built an exploit chain from cryptographic primitives, in a domain — mathematical reasoning — traditionally reserved for academic research.
Hanley summarized the model's distinctive capability: "Mythos excels at mathematical distillations and scientific tasks, especially those relating to computer science and operating systems." The systemic consequence is that defenders must now contend with flaws generated by tools that do not follow human heuristics, producing unexpected vectors through the composition of weaknesses considered separately non-critical. The compression of the patch window to under 24 hours suggests the gap between discovery and exploitation is shrinking to a margin organizations are not structured to manage.
Dossier Limits and Unresolved Points
The dossier does not specify whether Mythos autonomously generated the exploit proof-of-concept or if the practical implementation phase was conducted by Hanley with human support. The actual deployment of the patched version 3.2.1 among Rejetto HFS users is not documented, nor is it clear whether Anthropic issued a dedicated advisory for this CVE in its dashboard. The geographic origin of the Chinese IPs does not permit attribution to a specific actor: the source mentions proxies and known patterns but provides no elements to identify the operator.
Sources
- https://www.theregister.com/security/2026/10/03/anthropics-super-bug-hunting-model-mythos-is-hardcore-good-at-math-as-latest-vuln-under-attack-shows/5300933
- https://red.anthropic.com/2026/cvd/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search=rejetto&field_date_added_wrapper=all&field_cve=&sort_by=field_date_added&items_per_page=20&url=
- https://vimeo.com/1231352419?fl=pl&fe=vl
- https://www.theregister.com/security/2026/04/08/anthropic-mythos-model-can-find-and-exploit-0-days/5224393
Information verified against cited sources and current as of publication.
Sources
Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.