Find notable cyber news and cases, enriched with sources, timelines, and signals.
Vulnerability Exploitation Wave

Marimo WebSocket RCE abused after CVE-2026-39987 disclosure

Updated 29.05.2026 17:39
Case score 66
Case score 66 Members 2 Latest activity 29.05.2026 17:39
Active exploitation Patch available CVSS: 9.3 Critical
Members 2 First seen 10.04.2026 10:37 Last seen 12.04.2026 17:20 Updated 29.05.2026 17:39

Overview

**CVE-2026-39987** in **Marimo** is being exploited through the **/terminal/ws** endpoint to give unauthenticated attackers a shell on exposed notebook servers. The first observed abuse arrived about **9 hours and 41 minutes** after disclosure and moved into manual reconnaissance and secret-harvesting against internet-facing instances. Marimo released **0.23.0** to fix the flaw, and CISA added **CVE-2026-39987** to the KEV catalog with a **2026-05-07** remediation deadline. Available evidence does not quantify how many deployments were reached, but the observed behavior shows rapid weaponization against exposed systems.

Signals

4 derived
Impact signals
Affected schema and full contents of an internal PostgreSQL database
Exploitation
Exploitation Active exploitation CVSS 9.3 Critical
CVEs/products
CVE
Remediation
Remediation Patch available

Malware context

1 families

Member happenings

2 related
Vulnerability Marimo pre-authenticated RCE exploited (CVE-2026-39987)
Updated 10.04.2026 10:37 Lead Contribution 63
Exploitation Active Exploitation Exploit No Known Public Exploit Data Type Authentication Tokens Data Type Source Code +2

**Marimo**'s **CVE-2026-39987** now exposes internet-facing **/terminal/ws** instances to **unauthenticated remote code execution**, creating a path to a **full PTY shell** on affected servers. The flaw affects **all versions prior to and including 0.20.4** and was fixed in **0.23.0**. **Sysdig** observed exploitation **within 10 hours** of public disclosure, showing how quickly the vulnerability was weaponized.

Exploitation Wave Marimo CVE-2026-39987 exploitation wave
Updated 12.04.2026 17:20 Scoring Support Contribution 3
Exploitation Active Exploitation CVSS 9.3 Critical Patch Patch Available

**Marimo** exploitation activity surged **within 12 hours of disclosure**, with **125 IP addresses** beginning reconnaissance against **CVE-2026-39987** and the **/terminal/ws** exposure, raising the risk of rapid follow-on compromise. The wave quickly escalated into a **credential theft operation** that sought shell access and **.env** secrets. The activity matters because the flaw enables **unauthenticated remote code execution** on **Marimo versions 0.20.4 and earlier**. It also shows how quickly newly disclosed internet-facing weaknesses can draw broad probing and hands-on abuse.