CVE Tools
Back to feed
Exploited in the wild Marimo rce Redis

Human Attacker Exploits Marimo RCE, Reaches SSH Bastion in Eight Seconds

The Hacker News·By The Hacker News··3 min read
CVE Tools coverage

Sysdig observed a human-operated attack exploiting CVE-2026-39987, a pre-authentication RCE flaw affecting all versions of Marimo, to obtain AWS credentials and reach an SSH bastion host in eight seconds. The activity shows how rapidly operators can turn exposed notebook services into cloud access; separately, Hunt.io reported a cryptomining campaign compromising 3,562 Redis servers through unauthenticated rogue replication and deploying XMRig.

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store