Vulnerabilities · 74 days ago
The break is speed. One researcher is not just publishing exploits, they are using AI-automated fuzzing to turn unknown bugs into public proof-of-concepts fast enough that disclosure can lag behind exploit code. That shrinks the time defenders have to learn about a flaw before working examples are already circulating.
The repository, called Exploitarium, grew from about 15 PoCs to more than 30 over a few days and spans open-source projects including the Linux kernel, Libssh2, FFmpeg, Gogs, Gitea, Ghidra, 7-Zip, MyBB, PHP, OpenVPN and VLC. The researcher said they used OpenAI models and tools to automate the fuzzing process and did not notify maintainers first.
The forward risk is broader than this one repo. If AI can mass-produce PoCs across unrelated OSS projects, the window between unknown bug and public exploit code can collapse across the open-source supply chain.
CVEs in this update
10 CVEs
Across nmap, libssh2, Secure Connect Gateway, and related packages.
1 critical · 5 high · 3 medium · 1 low
0 in CISA KEV · 2 with EPSS above 1%
Highest severity: CVE-2026-58053 · 9.9 CRITICAL
Highest EPSS: CVE-2026-55200 · 4%
4 sources covering this story
Researcher Explains Release of Undisclosed Zero-Day Exploits
Infosecurity spoke with the researcher who dumped over 30 proof-of-concept exploits without disclosing the vulnerabilities first
Risky Bulletin: Researcher drops giant cache of zero-days
An anonymous researcher has dropped a giant cache of zero-day exploits, a sensitive DHS network got hacked, the US Supreme Court restricts [Read More
Anonymous researcher drops 0-day 'exploitarium' repo
At least two vulnerabilities are already under attack
Public PoC Released for Critical libssh2 CVE-2026-55200 Client-Side SSH Flaw
A public PoC for CVE-2026-55200 exposes a critical libssh2 flaw that can let a malicious SSH server corrupt client memory.
Part of the PlainSec briefing for 2026-07-03