Skip to content
Human Attacker Exploits Marimo RCE at Machine Speed

Human Attacker Exploits Marimo RCE at Machine Speed

First seen 14 Sep 2026, 16:51 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 14, 2026 at 17:55 UTC
  • CVE-2026-39987 exploited, allowing rapid SSH access.
  • Attacker executed over 850 commands in a nine-hour session.
  • Detection strategies must differentiate between human and AI-driven attacks.

A human attacker exploited CVE-2026-39987, a pre-authentication remote code execution vulnerability in Marimo notebooks, achieving a rapid transition from an open WebSocket to SSH access in just eight seconds. The attacker utilized a hand-rolled Python toolkit, bypassing detection mechanisms designed for AI-driven attacks. Over a nine-hour session, they executed more than 850 commands without using publicly available offensive tools. This incident highlights the potential for skilled human operators to match or exceed the speed of AI-assisted attacks. The vulnerability affects Marimo versions up to 0.20.4 and has been on CISA's Known Exploited Vulnerabilities catalog since April 2026. Sysdig's Threat Research Team documented the attack and provided recommendations for mitigating the risk. The incident emphasizes the need for robust detection strategies that account for both human and AI-driven threats.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-04-09
CVE-2026-39987 published
A pre-authentication remote code execution vulnerability in Marimo notebooks disclosed.
Sysdig
2026-04-13
First public PoC released
Proof-of-concept code for CVE-2026-39987 made publicly available.
Sysdig
2026-04-23
CVE added to CISA KEV catalog
CISA confirmed active exploitation of CVE-2026-39987 in the wild.
Sysdig
2026-09-11
Sysdig reports on human attacker
Sysdig's Threat Research Team published findings on a human attacker exploiting CVE-2026-39987.
Sysdig
2026-09-14
Incident reported in Infosecurity Magazine
Infosecurity Magazine detailed the human attacker's methods and implications for security.
Infosecurity-Magazine

More articles in this cluster (3)

Following this threat?

Track NKAbuse RAT, AWS and CVE-2026-39987 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed