LIVE FEED
CVE-2026-39987: Marimo RCE Exploited to Breach SSH Bastion

CVE-2026-39987: Marimo RCE Exploited to Breach SSH Bastion

ATLAS OWASP HIGH Significant risk · Prioritise patching ▲ 6.2 The Hacker News

A skilled human attacker exploited CVE-2026-39987, a pre-authenticated RCE vulnerability in the Marimo notebook platform, pivoting from initial access to an SSH bastion host in just eight seconds using hand-crafted Python tooling. Sysdig's research highlights that expert human operators can match the speed of AI-assisted attacks while demonstrating superior evasion capabilities, bypassing traps that consistently caught every agentic threat actor tested against the same CVE. The incident underscores the ongoing risk posed by interactive, notebook-style AI development environments as high-value attack surfaces in cloud-connected infrastructure.

◉ AI THREAT BRIEFING

Stay ahead of the threat.

Twice-weekly digest of critical AI security developments — every story mapped to MITRE ATLAS and OWASP LLM Top 10. Free.

No spam. Unsubscribe anytime.