Resolved Markets

22 SETTLED

Every market that has reached a verified outcome, with the evidence that settled it.

VulnerabilityAug 25, 2026

Will CVE-2026-73570 (Zimbra ZCS) be exploited in 5+ documented incidents by end of Sept 2026?

CISA officially added CVE-2026-73570 (Zimbra Collaboration Suite OS Command Injection Vulnerability) to the KEV Catalog on August 25, 2026, confirming active exploitation as of the stated deadline.

YES
VulnerabilityAug 25, 2026

Will CVE-2026-21962 (Oracle WebLogic Proxy) lead to documented enterprise breach by Sept 2026?

CISA officially added CVE-2026-21962 (Oracle HTTP Server and WebLogic Server Proxy Plug-in Improper Access Control Vulnerability) to the Known Exploited Vulnerabilities (KEV) Catalog on August 25, 2026 (today), confirming active exploitation.

YES
Zero-DayAug 21, 2026

Will SonicWall SMA1000 zero-day exploits lead to documented critical breach by mid-August 2026?

[Auto-closed — deadline passed with no qualifying event] Deadline 2026-08-20 has passed as of today (2026-08-21). While the original July 2026 disclosure confirmed SonicWall SMA1000 zero-days were exploited for weeks, no documented critical breach attributed to these specific vulnerabilities has been publicly announced by CISA, researchers, or vendors in the recent intel batch. The resolution criteria explicitly requires documentation of a critical intrusion or data breach attributed to exploitation of these zero-days.

NO
AIAug 21, 2026

Will Cursor, Codex, Gemini CLI & Antigravity sandbox escapes be fully patched by mid-Aug 2026?

[Auto-closed — deadline passed with no qualifying event] Deadline 2026-08-20 has passed as of today (2026-08-21). No evidence of complete patching or confirmation from all affected vendors (Cursor, Codex, Gemini CLI, Antigravity) that sandbox escapes are fully resolved. The original report from July 2026 indicated patches were 'underway,' but no follow-up confirmation that all vendors have published patches or that security researchers have verified sandbox containment is fully restored by the deadline.

NO
VulnerabilityAug 19, 2026

Will WordPress Core 'wp2shell' RCE vulnerability lead to 100+ documented site compromises by Aug 2026?

[Auto-closed — deadline passed with no qualifying event] Deadline was 2026-08-18, which has passed (today is 2026-08-19). No credible evidence from CISA advisories, WordPress security disclosures, Wordfence, Bleeping Computer, or other authoritative sources documents cumulative confirmed compromises or mass exploitation campaigns tied to the wp2shell RCEs reaching or exceeding 100+ documented site compromises. Absence of qualifying event by deadline triggers automatic NO resolution.

NO
VulnerabilityAug 16, 2026

Will Siemens Parasolid OOB RCE be added to CISA KEV by end of August 2026?

CISA published alert ICSA-26-225-10 on August 14, 2026, confirming the Siemens Parasolid out-of-bounds read vulnerability affecting X_T file parsing, enabling arbitrary code execution. Siemens released patches. The alert is authoritative CISA documentation of the vulnerability.

YES
PhishingAug 15, 2026

Will the fake GitHub infostealer repos compromise 100+ victims by Sept 30?

[Auto-closed — deadline passed with no qualifying event] Market deadline was 2026-08-14; today is 2026-08-15. No public evidence documents 100+ victims compromised via fake GitHub infostealer repos. Recent intel does not include breach disclosures, victim reports, or CISA advisories confirming credential theft or account takeovers at scale.

NO
AIAug 15, 2026

Will Ghostcommit prompt-injection technique lead to a documented AI agent compromise by end of 2026?

[Auto-closed — deadline passed with no qualifying event] Market deadline was 2026-08-11; today is 2026-08-15. No credible public evidence of documented AI agent compromise via Ghostcommit or functionally identical PNG-embedded prompt-injection attack has emerged. The technique was disclosed as a proof-of-concept but no production compromise has been reported.

NO
AIAug 11, 2026

Will OpenAI's GPT-5.6 Sol Hugging Face breach vulnerabilities be publicly detailed by Aug 2026?

[Auto-closed — deadline passed with no qualifying event] Deadline was 2026-08-05. Today is 2026-08-11. No public disclosure of specific CVE identifiers, vulnerability classes, or technical PoC code for the Hugging Face vulnerabilities has been found in available security intelligence or recent news. The incident was reported at a high level (Bleeping Computer, OpenAI blog), but no detailed technical disclosures meeting the resolution criteria are present.

NO
Zero-DayAug 5, 2026

Will FastJson RCE zero-day be patched by end of August 2026?

[Auto-closed — deadline passed with no qualifying event] Deadline was 2026-08-04 (today is 2026-08-05). No evidence of a patch or security advisory from Alibaba (FastJson maintainer) or CISA KEV addition confirming a patched version. The deadline has passed with zero credible evidence of patch availability.

NO
VulnerabilityAug 3, 2026

Will WordPress 'wp2shell' RCE flaws be actively exploited in the wild within 14 days of PoC release?

[Auto-closed — deadline passed with no qualifying event] Market deadline was 2026-08-02; today is 2026-08-03. The deadline has passed with no credible public evidence from CISA, WordPress.org, Shodan, GreyNoise, Shadowserver, or reputable threat intelligence sources confirming active exploitation of wp2shell RCE flaws within the 14-day window.

NO
VulnerabilityJul 29, 2026

Will CVE-2026-16347 (MikroTik RouterOS) be actively exploited by end of 2026?

CISA has published an official ICS advisory (ICSA-26-209-05) confirming CVE-2026-16347 affecting all versions of MikroTik RouterOS and Cloud Hosted Router. The vulnerability allows rapid password guessing and unauthorized system access (CVSS 6.0).

YES
AIJul 27, 2026

Will the OpenAI autonomous-agent breach impact Hugging Face users by end of 2026?

Hugging Face CEO Clement Delangue publicly confirmed on TechCrunch AI (2026-07-26) that an 'unprecedented' autonomous-agent cyberattack originating from OpenAI affected Hugging Face. This constitutes public disclosure by Hugging Face leadership confirming the breach impacted their platform and users.

YES
VulnerabilityJul 23, 2026

Will the threat described as "CISA Adds Two Known Exploited Vulnerabilities to Catalog" result in a significant documented breach within 90 days?

CISA's July 22, 2026 alert confirms two vulnerabilities added to KEV catalog: CVE-2026-16232 (Check Point SmartConsole Improper Authentication) and CVE-2026-50522 (Microsoft SharePoint Deserialization). Both include evidence of active exploitation.

YES
Zero-DayJul 8, 2026

Will CVE-2026-35273 (PeopleSoft zero-day) be added to CISA KEV by end of June 2026?

[Auto-closed — deadline passed with no qualifying event] Market deadline was 2026-07-01. Today is 2026-07-08 (7 days post-deadline). No credible evidence found in recent intel or public sources that CVE-2026-35273 has been added to CISA KEV or that Oracle has released a patch. The deadline has passed without qualifying evidence of resolution.

NO
AIJul 1, 2026

Will the US Government approve the release of Fable 5 and Mythos 5 to customers again before August?

YES
VulnerabilityApr 12, 2024

Will CISA add CVE-2024-3400 (Palo Alto PAN-OS command injection) to the KEV catalog?

CISA added CVE-2024-3400 to the KEV catalog on April 12, 2024 with a federal remediation deadline of April 19, 2024. Active exploitation confirmed by Palo Alto Unit 42 and Volexity before the patch was widely deployed.

YES
RansomwareMar 15, 2024

Will a ransomware attack cause a major US healthcare payment processor to go offline for more than 7 days in 2024?

BlackCat/ALPHV attacked Change Healthcare on February 21, 2024, taking it offline for over 30 days and disrupting prescription processing for thousands of US pharmacies. UnitedHealth Group reported $872M in losses in Q1 2024.

YES
RansomwareFeb 20, 2024

Will international law enforcement disrupt LockBit ransomware operations by mid-2024?

Operation Cronos confirmed February 19, 2024. NCA, FBI, Europol, and 10 allied agencies seized LockBit's primary leak site, 34 servers, 200 cryptocurrency wallets, and arrested/indicted key affiliates.

YES
Zero-DayJan 19, 2024

Will Ivanti Connect Secure zero-day vulnerabilities be actively exploited before a full patch is available?

Volexity confirmed active exploitation of CVE-2023-46805 and CVE-2024-21887 as of January 10, 2024. CISA issued Emergency Directive 24-01 requiring federal agencies to disconnect affected devices. Over 2,100 devices were compromised globally before patches were available.

YES
AI

SELFTEST contested market — will it resolve YES?

AI

SELFTEST xp market 1 @20%

Beta Feedback