Dossier
CVE-2026-39987
Coverage of CVE-2026-39987 in the Nexus archive.
- Attackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026-39987 Exploit
An unknown threat actor used an LLM agent for post-compromise actions after exploiting a publicly-accessible Marimo network via CVE-2026-39987, extracting cloud credentials from the compromised system.
- Marimo RCE Flaw CVE-2026-39987 Exploited Within 10 Hours of Disclosure
A critical remote code execution vulnerability (CVE-2026-39987) in Marimo, a Python data science notebook, was exploited within 10 hours of disclosure. The flaw affects all versions up to a specific release and was identified by Sysdig with a CVSS score of 9.3.