Claude Mythos Found a Critical HFS Bug, and Exploitation Followed Within a Day
Anthropic's vulnerability programme has disclosed 6,157 findings across 591 open-source projects. The HFS session-forgery bug shows what the programme's throughput means in practice: a publi
TL;DR
- Anthropic's coordinated vulnerability disclosure dashboard reported 6,157 vulnerabilities across 591 open-source projects as of 2026-10-02, with 516 patched and 584 identifiers issued.
- CVE-2026-61500 is a session-forgery flaw in Rejetto HFS 3.0.0 through 3.2.0: the cookie signing key comes from Math.random(), and the login handshake hands the attacker enough output to rebuild it.
- Horizon3 published the research on 2026-09-30 and reported no known exploitation. Canary traffic from a China-hosted IP against hosts in the United States and Japan appeared the next day.
- The fix had shipped on 2026-07-13, seventy-nine days before the write-up, which reframes the urgent number: what matters is the gap between publication and exploitation, not between discovery and disclosure.
- The dashboard says it plainly — independent human triage and review is the rate limiting step — so the programme's output is a queue an operator has to plan around.

A disclosure programme with a published ledger
Anthropic runs a programme that uses Claude models, including an early snapshot of Claude Mythos Preview, to find security flaws in open-source software. Findings go to external research firms for triage, then to maintainers privately, and detail is published once the disclosure window closes. The dashboard reports 6,157 vulnerabilities disclosed across 591 projects, 584 identifiers issued, of which 219 are CVE records and 365 are GitHub Security Advisories, and 516 findings patched to Anthropic's knowledge. Out of 29,439 candidate findings, 6,123 were reviewed and 5,674 confirmed, a 92.7% true-positive rate.
Two sentences on that page carry more operational weight than the headline. The first: the volume disclosed is a subset of what the models found, because independent human triage and review is the rate limiting step. The second: patches are the more reliable proxy for impact, but they are a lagging indicator, since patches take a long time to create. Triage partners on the programme include Ada Logics, Anvil, Calif.io, Doyensec, Ophion Security and Trail of Bits, and the programme publishes hash commitments so future disclosures can be checked against what was promised.
The programme itself was announced on 2026-04-07 with a partner list that reads like a critical-infrastructure roster — AWS, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, the Linux Foundation, Microsoft, NVIDIA and Palo Alto Networks — alongside up to $100M in usage credits and $4M in donations to open-source security organisations. Access was extended to more than forty additional organisations that maintain critical software. In an earlier round the model found a 27-year-old flaw in OpenBSD and a 16-year-old flaw in FFmpeg, in a line of code that automated testing had reportedly exercised five million times.
The flaw: a session key built from Math.random()
Rejetto HFS is a lightweight file-sharing server, and its 3.x line is a TypeScript and Node.js rewrite. When the administrator has not set COOKIE_SIGN_KEYS, the key that signs session cookies is generated with Math.random(), the non-cryptographic generator V8 uses, whose internal state is reversible from enough observed output. The login flow then hands out that output: during the unauthenticated loginSrp1 step the server sets a session id that is a raw Math.random() value. In the words of the write-up, the server returns "the exact 52-bit double in its own Set-Cookie".
VulnCheck's advisory is precise about the consequence: collect a small number of login responses, reconstruct the generator state, recover the signing key, and forge a valid administrator session cookie, which opens the administrative API and a code-execution path through server_code. The advisory carries CVSS 9.3 under CVSS 4.0 and credits Zach Hanley of Horizon3.ai, "in collaboration with Claude and Anthropic Research". The fix is HFS 3.2.1 or later; every release from 3.0.0 to 3.2.0 is affected.

Here is the fact worth pausing on, and it cuts against the obvious reading of the story. The fix came first. HFS 3.2.1 shipped on 2026-07-13, seventy-nine days before Horizon3 described how the model found the bug. The vulnerability was never a window of unpatched exposure for anyone who applied updates; it became dangerous the day the technique became public. Hanley's own framing is about economics: human researchers skip bugs like this for two reasons, a lack of mathematics expertise and "time and economic viability", and his conclusion is that "Mythos negates both of those reasons." The model's notes describe the work as a "standard publicly-tooled Z3/algebraic attack from ~3–5 consecutive doubles" — the tooling is public; the effort is what dropped.
How fast exploitation followed
Horizon3 published on 2026-09-30, and the published record at that moment recorded no in-the-wild exploitation. CISA's SSVC entry for the CVE noted no evidence of exploitation, and the flaw has not been added to the Known Exploited Vulnerabilities catalogue. That is the state a defender would have seen if they checked.
Then the canaries spoke. VulnCheck's Patrick Garrity, quoted in LavX News, wrote: "We started detecting exploitation of CVE-2026-61500 in Rejetto HFS this evening." His next line: "Our canaries detected an actor in China targeting real vulnerable hosts in the US." By the following day the same reporting describes four further attempts from two addresses in a single United States subnet, 173.239.211.248 and 173.239.211.249, which appear to be proxies. A day is not an eternity in patching terms, but it is shorter than most change-management cycles, which is the point of writing it down.
HFS has been hit before, which makes the speed less surprising. CVE-2024-23692, a template-injection flaw in the older HFS 2.3m line, has sat in CISA's Known Exploited Vulnerabilities catalogue since July 2024. The same internet-facing file server, the same administrative outcome, a two-year-old precedent.

Triage is the bottleneck, and patches are the lagging indicator
The programme's own numbers point at where the pressure sits. 6,157 findings disclosed, 516 patched: roughly one patch for every twelve disclosures. The dashboard is explicit that this is not a measure of maintainer negligence. It is arithmetic. A single open-source maintainer receiving several well-written vulnerability reports in a week has to triage, reproduce, patch, test and release, and none of that compresses as fast as model-driven discovery does.
Model availability reinforces the point about throughput rather than replacing it. Claude Mythos Preview is a restricted model; the Project Glasswing page lists access for the launch partners and more than forty further organisations, with participants reaching it on the Claude API, Amazon Bedrock, Google Cloud's Vertex AI and Microsoft Foundry at $25 per million input tokens and $125 per million output tokens. A defender who wants the offensive capability is not the buyer here; a defender who wants the defensive capability is, and the supply is deliberately limited while the models find faster than humans can fix.
What an operator should do this week
Treat the publication-to-exploitation gap as a number you own. The useful question after a disclosure like this one is not "are we patched?" but "how many days between a public write-up and a fixed, verified version in production, and who is on the hook for that number?" An advisory that says no known exploitation is a snapshot, not a guarantee, and the snapshot was worth roughly one day here.
Netics' position, from running monitoring for small estates, is that the cheap parts are inventory and visibility. Know every internet-facing instance of the affected product before the advisory lands, because that is the step that consumes the first hours. Keep the management interface on a private path, since the HFS attack needs the login endpoint reachable to collect the generator output. Watch the sources that matter, including the ones that publish between your patch window and the next one, and keep at least one eye on infrastructure monitoring with plain-language alerts, which is the layer that tells you an unfamiliar request pattern showed up on a service you had forgotten you exposed. Our earlier analysis of GTIG's vulnerability disclosure data looked at the same compression from the other side, in the volume of disclosures rather than the speed of exploitation.

The uncomfortable trade-off is honest. A model that finds flaws faster than a maintainer can patch them multiplies defensive work, and there is no version of this where the queue gets shorter just because discovery got cheaper. What a small team can control is its own reaction time, and that is measured in hours now.
Sources
Source: Anthropic coordinated vulnerability disclosure dashboard — red.anthropic.com/2026/cvd, last updated 2026-10-02 19:47 UTC (6,157 vulnerabilities disclosed across 591 projects, 516 patched, 584 identifiers including 219 CVE records and 365 GitHub Security Advisories, 29,439 candidates, 6,123 reviewed and 5,674 confirmed for a 92.7% true-positive rate; independent human triage and review as the rate limiting step; patches as a lagging indicator; triage partners and the disclosure ledger of hash commitments). Source: Project Glasswing — anthropic.com/glasswing, 2026-04-07 (partner list, up to $100M in usage credits and $4M in donations, access extended to more than forty further organisations, availability on the Claude API, Amazon Bedrock, Google Cloud's Vertex AI and Microsoft Foundry at $25/$125 per million tokens, the 27-year-old OpenBSD flaw, the 16-year-old FFmpeg flaw in a line automated testing had exercised five million times, and the assessment that AI models have reached a level of coding capability where they can surpass all but the most skilled humans at finding and exploiting vulnerabilities). Source: Rejetto HFS session forgery advisory — vulncheck.com/advisories/rejetto-hfs-session-forgery-via-predictable-signing-key, retrieved 2026-10-04 (affected range 3.0.0 to below 3.2.1, signing key derived from Math.random(), generator output disclosed to unauthenticated clients during login, administrator session forgery leading to remote code execution via server_code, CVSS 9.3, credit to Zach Hanley of Horizon3.ai in collaboration with Claude and Anthropic Research). Source: Mythos finds Rejetto HFS flaw later reported under attack — threatfrontier.com, retrieved 2026-10-04 (HFS 3.2.1 released 2026-07-13, 79 days before the write-up; randomId(30) from Math.random() when COOKIE_SIGN_KEYS is unset; the loginSrp1 session id as a raw generator value returning "the exact 52-bit double in its own Set-Cookie"; Z3 recovery of the xorshift128+ state; the user-enumeration bug found alongside; Horizon3 on Mythos creating "the working proof of concept exploit"; Hanley on mathematics expertise and "time and economic viability" with the conclusion that "Mythos negates both of those reasons"; the model's own description as a "standard publicly-tooled Z3/algebraic attack from ~3–5 consecutive doubles"; no exploitation recorded in CISA's SSVC entry; CVE-2024-23692 in the KEV catalogue since July 2024). Source: Anthropic's Mythos model finds critical HFS flaw; exploitation begins within 24 hours — news.lavx.hu, retrieved 2026-10-04 (VulnCheck's Patrick Garrity on detecting exploitation of CVE-2026-61500, canaries recording an actor in China targeting vulnerable hosts in the United States and Japan, and four further attempts from 173.239.211.248 and 173.239.211.249, in the same subnet and appearing to be proxies). Internal linkage: GTIG's AI-era vulnerability trends. More on Netics' work at neticslabs.com.
Source: Anthropic coordinated vulnerability disclosure dashboard — red.anthropic.com, 2026-10-02; Project Glasswing — anthropic.com, 2026-04-07; VulnCheck advisory for CVE-2026-61500 — vulncheck.com, retrieved 2026-10-04; Mythos and the Rejetto HFS flaw — threatfrontier.com, retrieved 2026-10-04; exploitation reporting — news.lavx.hu, retrieved 2026-10-04. Figures: official Anthropic and Google Cloud images, retrieved 2026-10-04.