A GitHub repository called "exploitarium", operated by the account bikini, has published a growing archive of uncoordinated zero-day proof-of-concept exploits affecting dozens of open-source and infrastructure projects before vendors could patch them. Reporting says the archive expanded beyond early public estimates to 35 project folders and 204 tracked files, with new targets continuing to appear at a pace of roughly two to three projects per week. The exposed attack surface spans libraries, kernel drivers, remote-access tools, web applications, and core infrastructure including PostgreSQL, Redis, Nextcloud, Discourse, Nmap, curl, AnyDesk, RustDesk, Git, and some PHP builds.
Researchers identified CVE-2026-55200 in libssh2 as one of the most serious issues in the archive: a pre-authentication out-of-bounds write in ssh2_transport_read() affecting libssh2 through 1.11.1, with an upstream fix referenced as commit 97acf3d. Because libssh2 is embedded transitively in widely used software such as curl and Git, the disclosures are being treated as a broader supply-chain exposure rather than a single incident. Assessments describe exploitarium as a lightly moderated multi-contributor clearinghouse that distributes unvetted exploit material at scale, prompting calls for urgent patching, software composition analysis, reachability-based remediation, and sustained monitoring.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
LevelBlue SpiderLabs reported that the libssh2 vulnerability highlighted in exploitarium had been fixed upstream by commit 97acf3d.
Researchers identified CVE-2026-55200 in libssh2 as a major finding from the archive: a pre-authentication out-of-bounds write in ssh2_transport_read() affecting libssh2 through version 1.11.1 and potentially enabling remote code execution.
By the time of assessment, researchers said exploitarium had grown beyond earlier reports of 130 PoCs to 35 tracked project folders containing 204 files.
The archive continued expanding into early July 2026, with new vulnerable projects being added as the repository grew.
LevelBlue SpiderLabs reported that the "exploitarium" GitHub archive began appearing publicly in late June 2026 as a mass uncoordinated vulnerability disclosure effort.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.