CRITICALVulnerability
Global

Marimo RCE Flaw CVE-2026-39987 Exploited Within 10 Hours of Disclosure

·Source: The Hacker News

Updated:

Executive Summary

A critical security vulnerability in Marimo, an open-source Python notebook for data science and analysis, has been exploited within 10 hours of public disclosure, according to findings from Sysdig. The vulnerability in question is CVE-2026-39987 (CVSS score: 9.3), a pre-authenticated remote code execution vulnerability impacting all versions of Marimo prior to and including

Analysis

A critical security vulnerability in Marimo, an open-source Python notebook for data science and analysis, has been exploited within 10 hours of public disclosure, according to findings from Sysdig. The vulnerability in question is CVE-2026-39987 (CVSS score: 9.3), a pre-authenticated remote code execution vulnerability impacting all versions of Marimo prior to and including

Indicators of Compromise (1)

CVE (1)
CVE-2026-39987
Source Attribution

Originally published by The Hacker News on Apr 10, 2026.

Related Threats