logo

CVE-2026-39987: Marimo RCE exploited in hours after disclosure

ID: f07cab5a-1f29-5164-9434-2b0d915bf49a

STIX ID: report--f07cab5a-1f29-5164-9434-2b0d915bf49a

Feed Name: Security Affairs

Threat Score
75/100

Date Published: 2026-04-11

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Marimo (CVE-2026-39987, CVSS 9.3) contains a pre-authentication RCE in its /terminal/ws WebSocket endpoint that was exploited within ~9 hours and 41 minutes of disclosure; attackers used the unauthenticated terminal to obtain shells and stole credentials in under three minutes, with Sysdig observing hands-on exploitation and providing IoCs and remediation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.