Mystery Geek Releases 0-Day ‘Exploitarium’ on GadgetLad

The Enigma Unveiled

Not everyone is enthusiastic about the entire responsible disclosure saga, right? An unnamed tech sorcerer released what they assert is executable exploit code for zero-day vulnerabilities in 15 software products and open source initiatives without alerting vendors or maintainers beforehand. Sounds like a complete nightmare, and cybercriminals are already having a field day with at least two of these exploits.

Severe RCE in libssh2

The first is CVE-2026-55200, a particularly vicious pre-authentication remote code execution (RCE) bug in libssh2, a well-known client-side C library that handles the core functions of the SSH2 protocol. Remote attackers can transmit faulty SSH packets with excessively large packet_length values, corrupt heap memory, and boom, they’ve achieved remote code execution. A patch has been incorporated into the libssh2 mainline development source control branch, and maintainers are still finalizing a release that will rectify this issue.

Authentication Bypass in Gitea Docker

The second is CVE-2026-20896, a severe authentication bypass vulnerability impacting self-hosted Gitea Docker instances. This one’s quite serious – allows unauthenticated remote attackers to impersonate any user and gain full command over the Git server. It’s addressed in Gitea version 1.26.3.

The Bikini Reveal

This tech maverick, who goes by bikini (unrelated to swimwear, of course), dropped the exploit code and vulnerability information in a now-removed GitHub repository named exploitarium. It brings to mind Nightmare Eclipse, the zero-day bug hunter who’s been releasing Microsoft exploits lately. However, bikini isn’t playing favorites, distributing alleged vulnerabilities across a variety of products and projects including libssh2, Splunk, RustDesk, 7-Zip, VLC, AnyDesk, OpenVPN, c-ares, Gitea, and Floci. Bikini asserted – and we at GadgetLad haven’t confirmed these assertions or the code’s validity – that none of the exploits in the repo have been reported. “Feel free to file reports yourself and claim the CVE if it’s granted lulz,” this enigmatic hacker remarked in a screenshot shared on X by Ledger CTO Charles Guillemet. “Please refrain from abusing these. My goal is to entice people into the field.” Of course, because nothing promotes “join the tech realm” quite like a security debacle, right?

The AI Angle

Other experts, such as Federal Signal analyst Ethan Andrews, speculated that bikini employed sophisticated AI models – specifically GPT-5.5 Codex – to automate fuzzing and discover vulnerabilities. Another sign that the AI-driven vulnpocalypse is just around the corner. Following bikini’s data release, Andrews created 44 KQL detection rules covering all from exploitarium, with adaptations for non-KQL frameworks.

Validation and Rejection

“The most technically significant discoveries – libssh2 pre-auth heap write and Gitea default Docker auth bypass – have been independently confirmed as high-risk with active exploitation noted,” Andrews observed. Some of the exploitarium releases “have been dismissed by the community as low-impact AI-fuzzing chatter.” Although GitHub has removed the repository, let’s be honest, nothing truly vanishes from the internet. Attackers are likely also utilizing AI to search for vulnerable instances. With bikini’s PoCs, they don’t even have to exert themselves to develop an exploit.

Conclusion

Exploitus Rumble: The Tech Clash

It appears someone has let the tech cat out of the bag, causing quite the uproar. In a landscape where everyone’s advocating for responsible disclosure, this mysterious geek is being reckless, and the internet is ablaze with it. As always, stay safe out there, tech explorers.