HIGHVulnerability
Verified
Global

CISA KEV: Marimo Marimo — Marimo Remote Code Execution Vulnerability

·Source: CISA KEV

Updated:

Executive Summary

Marimo contains an pre-authorization remote code execution vulnerability, allowing an unauthenticated attacked to shell access and execute arbitrary system commands.

Analysis

Marimo contains an pre-authorization remote code execution vulnerability, allowing an unauthenticated attacked to shell access and execute arbitrary system commands. Added to CISA Known Exploited Vulnerabilities catalog on 2026-04-23. Remediation due: 2026-05-07.

Indicators of Compromise (1)

CVE (1)
CVE-2026-39987
Source Attribution

Originally published by CISA KEV on Apr 23, 2026. Verified by: CISA.

Related Threats

CRITICALVulnerability

NVD CRITICAL: CVE-2024-13784 — The Contact Form, Survey, Quiz & Popup Form Builder – ARForms plugin for WordPre...

The Contact Form, Survey, Quiz & Popup Form Builder – ARForms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.8.5 via deserialization of untrusted input from form submissions. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no

CVE-2024-13784
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-18316 — The Solace Extra plugin for WordPress is vulnerable to unauthorized modification...

The Solace Extra plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the import_zip() function in versions up to, and including, 1.6.0. The handler is registered on both wp_ajax_action-import-zip and wp_ajax_nopriv_action-import-zip and only verifies the 'ajax-nonce' nonce, which is emitted on every admin page via wp_localize_script

CVE-2026-18316
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-18432 — The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege...

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.29.9. The vulnerability exists because `ActionUser::conditions_logic()` gates the `current_user_can('edit_user', $user_id)` authorization check behind an `is_numeric()` test, causing the check to be skipped entirely when `$user_id` is a non-numeric string — a conditio

CVE-2026-18432
NIST NVD