Find notable cyber news and cases, enriched with sources, timelines, and signals.
Vulnerability Exploitation Wave

Marimo WebSocket RCE abused after CVE-2026-39987 disclosure

Updated 29.05.2026 17:39
Case score 66
Members 2 First seen 10.04.2026 10:37 Latest activity 29.05.2026 17:39

Overview

**CVE-2026-39987** in **Marimo** is being exploited through the **/terminal/ws** endpoint to give unauthenticated attackers a shell on exposed notebook servers. The first observed abuse arrived about **9 hours and 41 minutes** after disclosure and moved into manual reconnaissance and secret-harvesting against internet-facing instances. Marimo released **0.23.0** to fix the flaw, and CISA added **CVE-2026-39987** to the KEV catalog with a **2026-05-07** remediation deadline. Available evidence does not quantify how many deployments were reached, but the observed behavior shows rapid weaponization against exposed systems.
Latest development Open development history 2 earlier developments Marimo discloses CVE-2026-39987 and early exploitation is observed Marimo identified CVE-2026-39987 as a CVSS 9.3 pre-authenticated remote code execution flaw in the /terminal/ws WebSocket endpoint, affecting all versions prior to and including 0.20.4 and fixed in 0.23.0; Sysdig then observed exploitation shortly after public disclosure, including a full PTY shell, manual reconnaissance, attempts to harvest .env data and SSH keys, and no proof-of-concept code available at the time.
  1. Earlier development

    Marimo releases version 0.23.0 to fix CVE-2026-39987

    Marimo released version 0.23.0 to address CVE-2026-39987 and advised users to upgrade immediately; if upgrading is not possible, external access to '/terminal/ws' should be blocked or disabled and exposed secrets should be rotated.

  2. Earlier development

    Sysdig reports hands-on exploitation and credential theft

    Sysdig researchers reported active exploitation that began less than 10 hours after disclosure, with 125 IP addresses starting reconnaissance within the first 12 hours. The first exploitation attempt validated remote code execution at '/terminal/ws', then continued with manual reconnaissance using pwd, whoami, and ls before targeting .env files, cloud credentials, application secrets, and SSH keys; the credential access phase finished in less than three minutes and no persistence was attempted.

Signals

Impact signals
Exploitation
CVEs/products
Geographic context
Remediation

Malware context

1 families

Technical intelligence

Existing Case data

Member happenings

Vulnerability Marimo pre-authenticated RCE exploited (CVE-2026-39987)
Updated 10.04.2026 10:37 Lead Contribution 63
Exploitation Active Exploitation Exploit No Known Public Exploit Data Type Authentication Tokens Data Type Source Code 2 more in details
All signals
Exploitation Active Exploitation Exploit No Known Public Exploit Data Type Authentication Tokens Data Type Source Code CVSS 9.3 Critical Patch Patch Available

**Marimo**'s **CVE-2026-39987** now exposes internet-facing **/terminal/ws** instances to **unauthenticated remote code execution**, creating a path to a **full PTY shell** on affected servers. The flaw affects **all versions prior to and including 0.20.4** and was fixed in **0.23.0**. **Sysdig** observed exploitation **within 10 hours** of public disclosure, showing how quickly the vulnerability was weaponized.

Exploitation Wave Marimo CVE-2026-39987 exploitation wave
Updated 12.04.2026 17:20 Scoring Support Contribution 3
Exploitation Active Exploitation CVSS 9.3 Critical Patch Patch Available

**Marimo** exploitation activity surged **within 12 hours of disclosure**, with **125 IP addresses** beginning reconnaissance against **CVE-2026-39987** and the **/terminal/ws** exposure, raising the risk of rapid follow-on compromise. The wave quickly escalated into a **credential theft operation** that sought shell access and **.env** secrets. The activity matters because the flaw enables **unauthenticated remote code execution** on **Marimo versions 0.20.4 and earlier**. It also shows how quickly newly disclosed internet-facing weaknesses can draw broad probing and hands-on abuse.