Vulnerabilities · 74 days ago

AI Fuzzing Turns One Dump Into Mass PoCs

The break is speed. One researcher is not just publishing exploits, they are using AI-automated fuzzing to turn unknown bugs into public proof-of-concepts fast enough that disclosure can lag behind exploit code. That shrinks the time defenders have to learn about a flaw before working examples are already circulating.

The repository, called Exploitarium, grew from about 15 PoCs to more than 30 over a few days and spans open-source projects including the Linux kernel, Libssh2, FFmpeg, Gogs, Gitea, Ghidra, 7-Zip, MyBB, PHP, OpenVPN and VLC. The researcher said they used OpenAI models and tools to automate the fuzzing process and did not notify maintainers first.

The forward risk is broader than this one repo. If AI can mass-produce PoCs across unrelated OSS projects, the window between unknown bug and public exploit code can collapse across the open-source supply chain.

CVEs in this update

10 CVEs

Across nmap, libssh2, Secure Connect Gateway, and related packages.

1 critical · 5 high · 3 medium · 1 low

0 in CISA KEV · 2 with EPSS above 1%

Highest severity: CVE-2026-58053 · 9.9 CRITICAL

Highest EPSS: CVE-2026-55200 · 4%

Timeline

Sources

4 sources covering this story

Entities

Part of the PlainSec briefing for 2026-07-03

Editions

Related stories