News

CVE-2026-39987: Marimo RCE exploited in hours after disclosure

  • Pierluigi Paganini--Securityaffairs.com
  • published date: 2026-04-11 09:44:44 UTC

A critical flaw, tracked as CVE-2026-39987, in the open-source Python notebook tool Marimo was exploited within 10 hours of disclosure. A critical flaw in Marimo, tracked as CVE-2026-39987 (CVSS score of 9.3) was exploited just 10 hours after disclosure (On A…

CVE-2026-39987: Marimo RCE exploited in hours after disclosure A critical flaw in Marimo, tracked as CVE-2026-39987 (CVSS score of 9.3) was exploited just 10 hours after disclosure (On April 8, 2026… [+3771 chars]