www.infosecurity-magazine.com 14 Sept 2026, 14:15 UTC

Human Attacker Hits Machine-Speed Exploitation of Marimo RCE

Human Attacker Hits Machine-Speed Exploitation of Marimo RCE
CyberSIXT Evidence Panel
CISA KEV Listed in KEV
Patch Patch Available

A human attacker successfully exploited a remote code execution flaw (CVE-2026-39987) in Marimo notebooks, moving from a vulnerable device to an SSH bastion host in just eight seconds. This speed, typically attributed to AI, was achieved with a hand-crafted toolkit. The attacker harvested cloud credentials from the notebook and executed commands over a nine-hour period, highlighting that human and AI attacks can look different while targeting the same vulnerabilities.

Recommendations include updating the software, improving authentication on the terminal endpoint, and managing permissions carefully. This flaw is listed in CISA's Known Exploited Vulnerabilities catalog, with remediation deadlines approaching.

View full article

Article by CyberSIXT