bytevyte
bytevyte
Language

AI-Assisted Vulnerability Discovery Cuts HFS Patch Window

AI-assisted vulnerability discovery found CVE-2026-61500 in Rejetto HFS. A China-linked actor exploited the 9.3-severity flaw within 24 hours.

AI-assisted vulnerability discovery
Photo by Cong Long Vu on Unsplash

A researcher's session with an AI model produced a critical authentication bypass in an open-source file server, and attackers were exploiting it within 24 hours of public disclosure. The flaw, tracked as CVE-2026-61500 and rated 9.3 on the CVSS scale, affects Rejetto HTTP File Server (HFS), a lightweight tool for sharing files over the web. The speed of that weaponization shows how far AI-assisted vulnerability discovery has compressed the warning window defenders once counted on.

Horizon3, the security firm that employs researcher Zach Hanley, credits him with the find. According to the company, he used Anthropic's restricted Mythos model to surface the bug, and the work turned a cryptographic exploit-development effort that would normally run for days into a single unguided session, with a formal-methods reasoning tool applied in an unusual way.

The defect itself is ordinary. HFS derives the signing key for its session cookies from a predictable random function, and its login flow hands the output of that non-cryptographic generator to unauthenticated clients. Collect enough of those outputs and the signing key can be reconstructed, an administrator session forged, and remote code execution reached on the host. Rejetto has shipped a fix in HFS version 3.2.1 and later, so deployments on earlier builds remain exposed.

VulnCheck, which tracks exploitation activity, has flagged the flaw as under active attack, according to the firm. The 9.3 score reflects unauthenticated reach combined with full administrative compromise: no credentials and no user interaction are needed, only network access to the server's login endpoint.

Within a day of disclosure, a China-linked threat actor was observed exploiting CVE-2026-61500 in the wild. That turnaround fits research CrowdStrike published in its 2026 threat report, which found China-linked groups including VAULT PANDA and GENESIS PANDA reaching same-day exploitation of critical web-application flaws and outrunning most corporate patch cycles.

Why the patch-to-exploit gap collapsed

The HFS case is not isolated. A cluster of 2026 vulnerabilities shows the same compression, with the gap between a fix and its exploitation measured in hours.

VulnerabilityProductTime from fix to exploitation
CVE-2026-61500Rejetto HFSUnder 24 hours
CVE-2026-33017Langflow20 hours
CVE-2026-19478GitLabUnder 24 hours
CVE-2026-87902WordPressWithin hours of patch release

Patch diffing compounds the problem. A published fix often reveals the weakness it repairs, and a model can read that diff and draft an exploit in minutes. That shifts the metric that matters: the interval between patch release and exploitation now carries more weight than the interval between discovery and exploitation. A fix can trigger an attack as easily as it ends one.

The longer trend is measurable. Eight years ago the average interval between discovering a software bug and exploiting it in an attack was 847 days, giving security teams more than two years to patch. That buffer is gone.

One capability drives both sides of the race. Models that read code and reason about logic help defenders find flaws at scale, and the same class of tooling helps attackers turn a patch diff into a working exploit. AI-assisted vulnerability discovery hands leverage to whoever moves first. Anthropic's Mythos points to a specific workflow, formal-methods reasoning applied to a codebase instead of pure pattern matching, which lets a model examine cryptographic weaknesses that have historically demanded sustained manual effort.

The asymmetry is structural. Defense requires finding and fixing every affected instance across an estate that often includes forgotten servers and unmanaged appliances. Offense needs one reachable, unpatched host. When discovery and weaponization both accelerate, the side that has to be right only once gains disproportionately.

Exposure to CVE-2026-61500 concentrates among smaller operators. HFS is popular with individual users, small businesses, and teams that stand up quick file-sharing endpoints without a dedicated security function. Those users are the least likely to track the CVE, test version 3.2.1, or notice an authentication bypass that leaves little obvious trace.

Stakes scale with deployment footprint. A separate remote-code-execution flaw in ServiceNow, tracked as CVE-2026-6875, drew attention because the platform runs more than 100 billion workflows annually and underpins AI applications at 85 percent of Fortune 500 companies. A defect in a widely embedded system turns a routine patch into a coordinated, high-stakes operation.

A different campaign showed the same dynamic from the attacker's side. One operator used AI agents to compromise 395 organizations through PaperCut print-server flaws, weaponizing them on August 31 before CISA added the bugs to its federal patch catalog four days later. Four days is not enough time for many educational institutions and small agencies to test and deploy a fix.

What defenders should change

Vulnerability management built on monthly patch cycles cannot absorb a 24-hour exploitation window. The practical response is to compress the interval between a fix and its deployment to hours for anything internet-facing, and to keep an accurate inventory of what is actually reachable from outside. Patching remains necessary. It is no longer sufficient on its own.

Compensating controls carry more weight in this environment. Network segmentation, removing unnecessary internet exposure from file servers, and monitoring for anomalous administrator sessions can blunt an exploit before a patch lands. Security teams are shifting budget toward breach and attack simulation, which tests whether existing defenses hold against techniques that emerge faster than any patch schedule can track.

AI-driven attacks are already appearing beyond server software. In South Korea, President Lee Jae Myung has directed an inquiry into an AI-enabled hacking campaign that struck seven financial institutions, a case that shows the same acceleration in the financial sector.

Why this matters

CVE-2026-61500 matters less as a single file-server bug than as a signal. When a model can find a critical flaw and attackers can weaponize it inside a day, an accurate asset inventory matters more and an unpatched internet-facing service becomes more dangerous. Decision-makers should treat 24-hour exploitation as the planning assumption rather than the worst case, and fund detection and containment alongside patching.

Photo by Cong Long Vu on Unsplash

✔Human Verified


Researched and cross-referenced against primary sources by the Bytevyte editorial team. This article was generated with the assistance of artificial intelligence and reviewed by the Bytevyte editorial team.