An anonymous GitHub account 'bikini' published the 'exploitarium' archive on June 23, 2026, containing 204 tracked PoC files across 35 open-source project folders without prior vendor notification. The most severe finding is CVE-2026-55200, a pre-authentication out-of-bounds write in libssh2's ssh2transportread() affecting versions through 1.11.1, with broad transitive exposure through curl, Git, and PHP. The archive has evolved into a multi-contributor clearinghouse accepting external research via pull requests and continues growing at 2-3 new project folders per week, with community KQL detection rules available via the Exploitarium-Detections project.
CVE-2026-55200
1 post
Exploitarium: Inside the Archive Behind the Mass 0-Day Drop