Posted inCybersecurity News
Marimo CVE-2026-39987 RCE exploited to bastion in 8s[9]
A human attacker abused Marimo's CVE-2026-39987 pre-auth RCE to pivot from an exposed WebSocket to an SSH bastion in eight seconds, highlighting urgent patch gaps.[9][1][3]













