levelblue.com • 2h
Exploitarium: Mass 0-Day PoC Release Affecting libssh2 and Open-Source Ecosystem
A security researcher known as "bikini" has released "Exploitarium," a public archive on GitHub containing Proof-of-Concept (PoC) exploits for over 15 open-source projects, bypassing Coordinated Vulnerability Disclosure (CVD) protocols. A primary highlight is CVE-2026-55200, a critical memory corruption vulnerability in libssh2 (up to v1.11.1) with a CVSS score of 9.2. This flaw allows a malicious SSH server to achieve unauthenticated Remote Code Execution (RCE) on connecting clients without user interaction. The immediate public availability of these PoCs significantly reduces the remediation window for vendors and increases the risk of rapid weaponization across the open-source software supply chain.