Exploited in the wild Marimo rce Redis
Human Attacker Exploits Marimo RCE, Reaches SSH Bastion in Eight Seconds
CVE Tools coverage
Sysdig observed a human-operated attack exploiting CVE-2026-39987, a pre-authentication RCE flaw affecting all versions of Marimo, to obtain AWS credentials and reach an SSH bastion host in eight seconds. The activity shows how rapidly operators can turn exposed notebook services into cloud access; separately, Hunt.io reported a cryptomining campaign compromising 3,562 Redis servers through unauthenticated rogue replication and deploying XMRig.