Close Menu
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    • Blogging
    • SEO & Digital Marketing
    • WiFi / Internet & Networking
    • Cybersecurity
    • Tech Tools & Mobile / Apps
    • Privacy & Online Earning
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    Home»Cybersecurity»Marimo RCE Flaw CVE-2026-39987 Exploited Within 10 Hours of Disclosure
    Cybersecurity

    Marimo RCE Flaw CVE-2026-39987 Exploited Within 10 Hours of Disclosure

    adminBy adminApril 11, 2026No Comments2 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    Marimo RCE Flaw CVE-2026-39987 Exploited Within 10 Hours of Disclosure
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananApr 10, 2026Vulnerability / Threat Intelligence

    A critical security vulnerability in Marimo, an open-source Python notebook for data science and analysis, has been exploited within 10 hours of public disclosure, according to findings from Sysdig.

    The vulnerability in question is CVE-2026-39987 (CVSS score: 9.3), a pre-authenticated remote code execution vulnerability impacting all versions of Marimo prior to and including 0.20.4. The issue has been addressed in version 0.23.0.

    “The terminal WebSocket endpoint /terminal/ws lacks authentication validation, allowing an unauthenticated attacker to obtain a full PTY shell and execute arbitrary system commands,” Marimo maintainers said in an advisory earlier this week.

    “Unlike other WebSocket endpoints (e.g., /ws) that correctly call validate_auth() for authentication, the /terminal/ws endpoint only checks the running mode and platform support before accepting connections, completely skipping authentication verification.”

    In other words, attackers can obtain a full interactive shell on any exposed Marimo instance through a single WebSocket connection without requiring any credentials.

    Sysdig said it observed the first exploitation attempt targeting the vulnerability within 9 hours and 41 minutes of it being publicly disclosed, with a credential theft operation executed in minutes, despite there being no proof-of-concept (PoC) code available at the time.

    The unknown threat actor behind the activity is said to have connected to the /terminal/ws WebSocket endpoint on a honeypot system and initiated manual reconnaissance to explore the file system and, minutes later, systematically attempted to harvest data from the .env file, as well as search for SSH keys and read various files.

    The attacker returned to the honeypot an hour later to access the contents of the .env file and check if other threat actors were active during the time window. No other payloads, like cryptocurrency miners or backdoors, were installed.

    “The attacker built a working exploit directly from the advisory description, connected to the unauthenticated terminal endpoint, and began manually exploring the compromised environment,” the cloud security company said. “The attacker connected four times over 90 minutes, with pauses between sessions. This is consistent with a human operator working through a list of targets, returning to confirm findings.”

    The speed at which newly disclosed flaws are being weaponized indicates that threat actors are closely keeping an eye on vulnerability disclosures and quickly exploiting them during the time between disclosure and patch adoption.This, in turn, has shrunk the time defenders must respond once a vulnerability is publicly announced.

    “The assumption that attackers only target widely deployed platforms is wrong. Any internet-facing application with a critical advisory is a target, regardless of its popularity.”

    CVE202639987 Disclosure Exploited Flaw hours Marimo RCE
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleA bunch of Ring security cameras are on sale! Come get them!
    Next Article AI demand is so high, AWS customers are trying to buy out its entire capacity
    admin
    • Website

    Related Posts

    Encryption Consulting launches CertSecure Manager v3.3 with zero-touch certificate renewals

    May 20, 2026

    GitHub confirms breach of 3,800 repos via malicious VSCode extension

    May 20, 2026

    Grafana GitHub Breach Exposes Source Code via TanStack npm Attack

    May 20, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Search Blog
    About
    About

    At WifiPortal.tech, we share simple, easy-to-follow guides on cybersecurity, online privacy, and digital opportunities. Our goal is to help everyday users browse safely, protect personal data, and explore smart ways to earn online. Whether you’re new to the digital world or looking to strengthen your online knowledge, our content is here to keep you informed and secure.

    Trending Blogs

    MIT Research Shows The Shift Reshaping SEO Strategy

    June 2, 2026

    Commerce media expands beyond retail sites with Demand Gen integration

    June 2, 2026

    The 50 Most-Cited Websites in Perplexity (June 2026)

    June 2, 2026

    FTC broadens Microsoft probe to cloud, AI, and software bundling

    June 2, 2026
    Categories
    • Blogging (88)
    • Cybersecurity (1,955)
    • Privacy & Online Earning (230)
    • SEO & Digital Marketing (1,336)
    • Tech Tools & Mobile / Apps (1,796)
    • WiFi / Internet & Networking (323)

    Subscribe to Updates

    Stay updated with the latest tips on cybersecurity, online privacy, and digital opportunities straight to your inbox.

    WifiPortal.tech is a blogging platform focused on cybersecurity, online privacy, and digital opportunities. We share easy-to-follow guides, tips, and resources to help you stay safe online and explore new ways of working in the digital world.

    Our Picks

    MIT Research Shows The Shift Reshaping SEO Strategy

    June 2, 2026

    Commerce media expands beyond retail sites with Demand Gen integration

    June 2, 2026

    The 50 Most-Cited Websites in Perplexity (June 2026)

    June 2, 2026
    Most Popular
    • MIT Research Shows The Shift Reshaping SEO Strategy
    • Commerce media expands beyond retail sites with Demand Gen integration
    • The 50 Most-Cited Websites in Perplexity (June 2026)
    • FTC broadens Microsoft probe to cloud, AI, and software bundling
    • Google expands Data Manager API with GMP event ingestion
    • The 50 Most-Cited Websites in Copilot (June 2026)
    • What Google’s New AI Guide Actually Debunks. And What It Doesn’t
    • Broadcom, Samsung team for wireless SoC
    © 2026 WifiPortal.tech. Designed by WifiPortal.tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.