THREAT OPS › CVEs › CVE-2026-39987
CVE-2026-39987 — Marimo Remote Code Execution Vulnerability
Marimo contains an pre-authorization remote code execution vulnerability, allowing an unauthenticated attacked to shell access and execute arbitrary system commands.
Vulnerability details
- Affected productsMarimo
- KEV remediation due2026-05-07
Related reporting
- August 2026 CVE Landscaperecordedfuture
- Attackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026-39987 Exploitai_incident_db
- The Agentic AI threat cluster: Seven incidents, three actors, and what they mean for your exposuretenable
- July 2026 CVE Landscaperecordedfuture
- April 2026 CVE Landscaperecordedfuture