Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This two-file repository contains a README and a standalone Python proof of concept for CVE-2026-102975, an authorization bypass in MediaWiki's RevisionDelete API. The PoC logs in as a deliberately limited account that has viewsuppressed and deleterevision but lacks suppressrevision, then submits a revisiondelete request with suppress=no. It verifies exploitation by checking whether an anonymous API query can retrieve a known canary from the formerly suppressed revision. A separately authenticated administrator with suppressrevision is used for best-effort cleanup to restore suppression. The script includes substantial safeguards: it accepts only localhost or IP loopback base URLs, rejects credentials/query strings in the base URL, validates redirect destinations remain loopback, requires a matching disposable page/revision fixture, confirms pre-existing suppression, prompts for passwords, and requires an exact typed confirmation before making the visibility change. No external network target, hard-coded host, shell payload, persistence, or command execution capability is present.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.