Marimo is a technology platform tracked across 5 threat clusters and 10 intelligence report mentions on ThreatCluster. First observed April 11, 2026; most recent activity June 9, 2026.
A critical pre-authentication remote code execution (RCE) vulnerability in Marimo, an open-source Python notebook platform, was disclosed on April 8, 2026, and exploited within 9 hours and 41 minutes. The vulnerability,…
On April 8, 2026, a critical pre-authenticated remote code execution vulnerability (CVE-2026-39987) was disclosed in Marimo, an open-source Python notebook platform. The flaw allows unauthenticated attackers to gain a…
A critical vulnerability in the Marimo Python notebook framework, tracked as CVE-2026-39987, allows attackers to execute arbitrary commands remotely without authentication. The flaw, stemming from a missing…
On May 10, 2026, threat actors exploited CVE-2026-39987, a remote code execution vulnerability in the marimo notebook environment, to gain unauthorized access to internal databases. The attackers utilized a large…
Researchers at the University of Toronto have developed a self-replicating AI worm that autonomously exploits network vulnerabilities. This malware utilizes a small, free large language model (LLM) to devise unique…