Researchers at VulnCheck have observed probes targeting the vulnerability, with a single China Telecom IP address conducting reconnaissance on deployments in Japan and the United States. The activity appears to be small-scale scanning so far, but the release of technical details and a proof-of-concept exploit by Horizon3 on September 30, 2026, may have prompted the interest.
The flaw stems from HFS's use of the non-cryptographic Math.random() generator to derive session-cookie signing keys, while simultaneously leaking outputs of the same generator to unauthenticated clients during login. A remote attacker can collect a small number of login responses, reconstruct the generator's state, recover the signing key, and forge a valid administrator session cookie. This grants full administrative access, including the ability to execute code via the server_code configuration feature.
"Mythos didn't just flag the insecure PRNG in isolation – it simultaneously identified that the application leaked raw Math.random() outputs through a separate code path, recognized those two facts as a chain, and determined the leak produced exactly the observations needed to make state recovery feasible," explained Horizon3 in their disclosure.
Attack scenarios include accessing, stealing, or deleting files on the HFS server, installing malware, or using the compromised host to pivot to internal networks. VulnCheck has not yet reported successful exploitation or post-exploitation activity. Users are recommended to upgrade to version 3.2.1 or, ideally, the latest stable release, 3.3.4.