# CVE-2026-39987

Published articles for CVE-2026-39987.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Machine speed, hold the AI: Hand-rolled marimo CVE-2026-39987 exploit

DevFeed: [Machine speed, hold the AI: Hand-rolled marimo CVE-2026-39987 exploit](<https://devfeed.tech/articles/machine-speed-hold-the-ai-hand-rolled-marimo-cve-2026-39987-exploit-53246.md>)

Original publisher: [Read original article](<https://webflow.sysdig.com/blog/machine-speed-hold-the-ai-hand-rolled-marimo-cve-2026-39987-exploit>)

Author: Sysdig Threat Research Team

Published: 2026-09-11T00:00:00Z

Content type: article

Language: en

Sources: [Sysdig](<https://devfeed.tech/sources/sysdig-blog.md>)

Topics: [CVE-2026-39987](<https://devfeed.tech/topics/cve-2026-39987.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>), [Python](<https://devfeed.tech/topics/python.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>)

Tags: [aws-secrets-manager](<https://devfeed.tech/tags/aws-secrets-manager.md>), [bastion-host](<https://devfeed.tech/tags/bastion-host.md>), [cisa-kev](<https://devfeed.tech/tags/cisa-kev.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [cloud-credential-theft](<https://devfeed.tech/tags/cloud-credential-theft.md>), [cve-2026-39987](<https://devfeed.tech/tags/cve-2026-39987.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [human-operated-attack](<https://devfeed.tech/tags/human-operated-attack.md>), [llm-driven-attack](<https://devfeed.tech/tags/llm-driven-attack.md>), [marimo-cve-2026-39987](<https://devfeed.tech/tags/marimo-cve-2026-39987.md>), [marimo-rce](<https://devfeed.tech/tags/marimo-rce.md>), [notebook-security](<https://devfeed.tech/tags/notebook-security.md>), [python](<https://devfeed.tech/tags/python.md>), [remote-code-execution](<https://devfeed.tech/tags/remote-code-execution.md>), [remote-code-execution-vulnerability](<https://devfeed.tech/tags/remote-code-execution-vulnerability.md>), [ssh-bastion-host](<https://devfeed.tech/tags/ssh-bastion-host.md>), [sysdig-threat-research-team](<https://devfeed.tech/tags/sysdig-threat-research-team.md>), [websocket-authentication-bypass](<https://devfeed.tech/tags/websocket-authentication-bypass.md>)

### AI overview

Sysdig's Threat Research Team documents a hand-crafted attack exploiting marimo's CVE-2026-39987. The operator used custom Python tooling to obtain remote code execution, access AWS Secrets Manager, retrieve a private key, and reach a bastion host in eight seconds.

### Source excerpt

Sysdig TRT details a hand-rolled attack against marimo's CVE-2026-39987 without AI, building custom Python tools to breach a cloud bastion host.

## \[webapps\] Marimo 0.20.4 - RCE

DevFeed: [\[webapps\] Marimo 0.20.4 - RCE](<https://devfeed.tech/articles/webapps-marimo-0-20-4-rce-34766.md>)

Original publisher: [Read original article](<https://www.exploit-db.com/exploits/52673>)

Author: Jason Bernier

Published: 2026-09-02T00:00:00Z

Content type: article

Language: en

Sources: [Exploit-DB.com RSS Feed](<https://devfeed.tech/sources/exploit-db-com-rss-feed.md>)

Topics: [CVE-2026-39987](<https://devfeed.tech/topics/cve-2026-39987.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>), [Web app](<https://devfeed.tech/topics/webapp.md>)

Tags: [cve](<https://devfeed.tech/tags/cve.md>), [cve-2026-39987](<https://devfeed.tech/tags/cve-2026-39987.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [multiple](<https://devfeed.tech/tags/multiple.md>), [webapps](<https://devfeed.tech/tags/webapps.md>)

### AI overview

An Exploit Database entry reports a remote code execution issue involving Marimo 0.20.4, identified as CVE-2026-39987.

### Source excerpt

Marimo 0.20.4 - RCE

## Four ways AI has fundamentally changed the threat landscape in 2026

DevFeed: [Four ways AI has fundamentally changed the threat landscape in 2026](<https://devfeed.tech/articles/four-ways-ai-has-fundamentally-changed-the-threat-landscape-in-2026-53221.md>)

Original publisher: [Read original article](<https://webflow.sysdig.com/blog/four-ways-ai-has-fundamentally-changed-the-threat-landscape-in-2026>)

Author: Crystal Morin

Published: 2026-07-21T00:00:00Z

Content type: article

Language: en

Sources: [Sysdig](<https://devfeed.tech/sources/sysdig-blog.md>)

Topics: [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [AI Agent](<https://devfeed.tech/topics/ai-agent.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [CVE-2026-39987](<https://devfeed.tech/topics/cve-2026-39987.md>), [Database](<https://devfeed.tech/topics/database.md>), [ssh](<https://devfeed.tech/topics/ssh.md>)

Tags: [555-benchmark](<https://devfeed.tech/tags/555-benchmark.md>), [abliterated-models](<https://devfeed.tech/tags/abliterated-models.md>), [agentic-ai](<https://devfeed.tech/tags/agentic-ai.md>), [agentic-ai-attacks](<https://devfeed.tech/tags/agentic-ai-attacks.md>), [agentic-ransomware](<https://devfeed.tech/tags/agentic-ransomware.md>), [agentic-threat-actor](<https://devfeed.tech/tags/agentic-threat-actor.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-bill-of-materials](<https://devfeed.tech/tags/ai-bill-of-materials.md>), [ai-infrastructure-security](<https://devfeed.tech/tags/ai-infrastructure-security.md>), [aibom](<https://devfeed.tech/tags/aibom.md>), [cloud-detection-and-response](<https://devfeed.tech/tags/cloud-detection-and-response.md>), [credentials](<https://devfeed.tech/tags/credentials.md>), [cve-2026-39987](<https://devfeed.tech/tags/cve-2026-39987.md>), [cve-exploitation-timeline](<https://devfeed.tech/tags/cve-exploitation-timeline.md>), [jadepuffer](<https://devfeed.tech/tags/jadepuffer.md>), [langflow-rce](<https://devfeed.tech/tags/langflow-rce.md>), [litellm-sql-injection](<https://devfeed.tech/tags/litellm-sql-injection.md>), [llm-jailbreaking](<https://devfeed.tech/tags/llm-jailbreaking.md>), [llmjacking](<https://devfeed.tech/tags/llmjacking.md>), [lmdeploy-ssrf](<https://devfeed.tech/tags/lmdeploy-ssrf.md>), [marimo-vulnerability](<https://devfeed.tech/tags/marimo-vulnerability.md>), [ollama-exposure](<https://devfeed.tech/tags/ollama-exposure.md>), [private-key](<https://devfeed.tech/tags/private-key.md>), [runtime-visibility](<https://devfeed.tech/tags/runtime-visibility.md>), [ssh](<https://devfeed.tech/tags/ssh.md>), [sysdig-threat-research-team](<https://devfeed.tech/tags/sysdig-threat-research-team.md>), [sysdig-trt](<https://devfeed.tech/tags/sysdig-trt.md>)

### AI overview

Sysdig's Threat Research Team documents four ways agentic AI is changing the threat landscape, including autonomous attacks that plan, execute, and adapt in real time. The supplied evidence describes an incident in which an agent moved from a marimo vulnerability to database exfiltration in under an hour.

### Source excerpt

Sysdig TRT documents four ways agentic AI is reshaping the threat landscape -- from autonomous attackers to AI infrastructure as prime target.

## Agentic threat actor hits the orchestration plane: AI agent-driven container escape

DevFeed: [Agentic threat actor hits the orchestration plane: AI agent-driven container escape](<https://devfeed.tech/articles/agentic-threat-actor-hits-the-orchestration-plane-ai-agent-driven-container-escape-53193.md>)

Original publisher: [Read original article](<https://webflow.sysdig.com/blog/agentic-threat-actor-hits-the-orchestration-plane-ai-agent-driven-container-escape>)

Author: Michael Clark

Published: 2026-06-04T00:00:00Z

Content type: article

Language: en

Sources: [Sysdig](<https://devfeed.tech/sources/sysdig-blog.md>)

Topics: [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [AI Agent](<https://devfeed.tech/topics/ai-agent.md>), [Large Language Model](<https://devfeed.tech/topics/llm.md>), [container escape](<https://devfeed.tech/topics/container-escape.md>), [container](<https://devfeed.tech/topics/container.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Docker](<https://devfeed.tech/topics/docker.md>), [CVE-2026-39987](<https://devfeed.tech/topics/cve-2026-39987.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [agentic](<https://devfeed.tech/tags/agentic.md>), [agentic-attacker-orchestration-plane-takeover](<https://devfeed.tech/tags/agentic-attacker-orchestration-plane-takeover.md>), [agentic-threat-actor](<https://devfeed.tech/tags/agentic-threat-actor.md>), [ai-agent](<https://devfeed.tech/tags/ai-agent.md>), [ai-driven-container-escape](<https://devfeed.tech/tags/ai-driven-container-escape.md>), [automated-container-escape-kill-chain-2026](<https://devfeed.tech/tags/automated-container-escape-kill-chain-2026.md>), [cloud-native-post-exploitation](<https://devfeed.tech/tags/cloud-native-post-exploitation.md>), [container-escape](<https://devfeed.tech/tags/container-escape.md>), [container-escape-ttps](<https://devfeed.tech/tags/container-escape-ttps.md>), [containers](<https://devfeed.tech/tags/containers.md>), [copy-fail-lpe](<https://devfeed.tech/tags/copy-fail-lpe.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cve-2026-39987](<https://devfeed.tech/tags/cve-2026-39987.md>), [cve-2026-39987-marimo-exploit](<https://devfeed.tech/tags/cve-2026-39987-marimo-exploit.md>), [docker](<https://devfeed.tech/tags/docker.md>), [docker-socket-escape](<https://devfeed.tech/tags/docker-socket-escape.md>), [exploitation](<https://devfeed.tech/tags/exploitation.md>), [how-attackers-use-llms-to-escape-containers](<https://devfeed.tech/tags/how-attackers-use-llms-to-escape-containers.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [kubernetes-secret-store-exfiltration](<https://devfeed.tech/tags/kubernetes-secret-store-exfiltration.md>), [kubernetes-service-account-token-abuse-cloud-attack](<https://devfeed.tech/tags/kubernetes-service-account-token-abuse-cloud-attack.md>), [kubernetes-service-account-token-replay](<https://devfeed.tech/tags/kubernetes-service-account-token-replay.md>), [llm](<https://devfeed.tech/tags/llm.md>), [llm-attack-automation](<https://devfeed.tech/tags/llm-attack-automation.md>), [marimo-notebook-rce](<https://devfeed.tech/tags/marimo-notebook-rce.md>), [mounted-docker-socket-container-escape-attack](<https://devfeed.tech/tags/mounted-docker-socket-container-escape-attack.md>), [nsenter-namespace-breakout](<https://devfeed.tech/tags/nsenter-namespace-breakout.md>), [privileged-container-breakout](<https://devfeed.tech/tags/privileged-container-breakout.md>), [rbac-misconfiguration](<https://devfeed.tech/tags/rbac-misconfiguration.md>), [research](<https://devfeed.tech/tags/research.md>), [secrets](<https://devfeed.tech/tags/secrets.md>), [t1078-004-valid-accounts-cloud-accounts](<https://devfeed.tech/tags/t1078-004-valid-accounts-cloud-accounts.md>), [t1552-007-container-api-secrets](<https://devfeed.tech/tags/t1552-007-container-api-secrets.md>), [t1610-deploy-container](<https://devfeed.tech/tags/t1610-deploy-container.md>), [t1613-container-and-resource-discovery](<https://devfeed.tech/tags/t1613-container-and-resource-discovery.md>)

### AI overview

Sysdig Threat Research Team reports an LLM-driven threat actor exploiting a vulnerable marimo notebook, escaping a container to the host, and replaying a Kubernetes service-account token to dump the cluster's secrets.

### Source excerpt

Sysdig TRT caught an LLM-driven attacker escaping containers, breaking out to the host, and dumping Kubernetes secrets, no human required.

## AI agent at the wheel: How an attacker used LLMs to move from a CVE to an internal database in 4 pivots

DevFeed: [AI agent at the wheel: How an attacker used LLMs to move from a CVE to an internal database in 4 pivots](<https://devfeed.tech/articles/ai-agent-at-the-wheel-how-an-attacker-used-llms-to-move-from-a-cve-to-an-internal-database-in-4-pivots-53195.md>)

Original publisher: [Read original article](<https://webflow.sysdig.com/blog/ai-agent-at-the-wheel-how-an-attacker-used-llms-to-move-from-a-cve-to-an-internal-database-in-4-pivots>)

Author: Michael Clark

Published: 2026-05-26T00:00:00Z

Content type: article

Language: en

Sources: [Sysdig](<https://devfeed.tech/sources/sysdig-blog.md>)

Topics: [AI Agent](<https://devfeed.tech/topics/ai-agent.md>), [Large Language Model](<https://devfeed.tech/topics/llm.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [CVE-2026-39987](<https://devfeed.tech/topics/cve-2026-39987.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Cloudflare Workers](<https://devfeed.tech/topics/cloudflare-workers.md>), [Amazon Web Services](<https://devfeed.tech/topics/aws.md>), [PostgreSQL](<https://devfeed.tech/topics/postgresql.md>), [OpenSSH](<https://devfeed.tech/topics/openssh.md>)

Tags: [adaptive-attacker-ttps](<https://devfeed.tech/tags/adaptive-attacker-ttps.md>), [agent](<https://devfeed.tech/tags/agent.md>), [agent-driven-intrusion-kubernetes](<https://devfeed.tech/tags/agent-driven-intrusion-kubernetes.md>), [ai-agent](<https://devfeed.tech/tags/ai-agent.md>), [ai-agent-lateral-movement-cloud](<https://devfeed.tech/tags/ai-agent-lateral-movement-cloud.md>), [ai-driven-intrusion](<https://devfeed.tech/tags/ai-driven-intrusion.md>), [aws](<https://devfeed.tech/tags/aws.md>), [aws-secrets-manager-exploit](<https://devfeed.tech/tags/aws-secrets-manager-exploit.md>), [cloud-api-enumeration](<https://devfeed.tech/tags/cloud-api-enumeration.md>), [cloud-credential-theft](<https://devfeed.tech/tags/cloud-credential-theft.md>), [cloudflare-workers](<https://devfeed.tech/tags/cloudflare-workers.md>), [cloudflare-workers-egress-pool](<https://devfeed.tech/tags/cloudflare-workers-egress-pool.md>), [credential-access-t1552](<https://devfeed.tech/tags/credential-access-t1552.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cve-2026-39987](<https://devfeed.tech/tags/cve-2026-39987.md>), [egress](<https://devfeed.tech/tags/egress.md>), [exfiltration-via-command-and-scripting-interpreter](<https://devfeed.tech/tags/exfiltration-via-command-and-scripting-interpreter.md>), [falco](<https://devfeed.tech/tags/falco.md>), [llm-agent-attack](<https://devfeed.tech/tags/llm-agent-attack.md>), [llm-assisted-threat-actor](<https://devfeed.tech/tags/llm-assisted-threat-actor.md>), [llm-powered-cyberattack-detection](<https://devfeed.tech/tags/llm-powered-cyberattack-detection.md>), [llms](<https://devfeed.tech/tags/llms.md>), [marimo-notebook-vulnerability](<https://devfeed.tech/tags/marimo-notebook-vulnerability.md>), [marimo-rce-cve-patch](<https://devfeed.tech/tags/marimo-rce-cve-patch.md>), [post-exploitation-automation](<https://devfeed.tech/tags/post-exploitation-automation.md>), [postgresql](<https://devfeed.tech/tags/postgresql.md>), [postgresql-exfiltration](<https://devfeed.tech/tags/postgresql-exfiltration.md>), [private-key](<https://devfeed.tech/tags/private-key.md>), [real-time-ai-attack-chain-cloud-environment](<https://devfeed.tech/tags/real-time-ai-attack-chain-cloud-environment.md>), [secrets](<https://devfeed.tech/tags/secrets.md>), [ssh](<https://devfeed.tech/tags/ssh.md>), [ssh-bastion-attack](<https://devfeed.tech/tags/ssh-bastion-attack.md>), [threat-research](<https://devfeed.tech/tags/threat-research.md>)

### AI overview

A Sysdig Threat Research Team investigation describes an intrusion in which an LLM agent drove post-exploitation activity. The attack used CVE-2026-39987, cloud credentials, AWS Secrets Manager, Cloudflare Workers, SSH sessions, and a bastion host to exfiltrate an internal PostgreSQL database in under one hour.

### Source excerpt

A Sysdig TRT investigation reveals their first seen LLM-agent-driven intrusion: from CVE-2026-39987 to internal database exfiltration in under one hour.

## Marimo OSS Python Notebook RCE: From Disclosure to Exploitation in Under 10 Hours

DevFeed: [Marimo OSS Python Notebook RCE: From Disclosure to Exploitation in Under 10 Hours](<https://devfeed.tech/articles/marimo-oss-python-notebook-rce-from-disclosure-to-exploitation-in-under-10-hours-53248.md>)

Original publisher: [Read original article](<https://webflow.sysdig.com/blog/marimo-oss-python-notebook-rce-from-disclosure-to-exploitation-in-under-10-hours>)

Author: Sysdig Threat Research Team

Published: 2026-04-09T00:00:00Z

Content type: news

Language: en

Sources: [Sysdig](<https://devfeed.tech/sources/sysdig-blog.md>)

Topics: [Python](<https://devfeed.tech/topics/python.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>), [WebSocket](<https://devfeed.tech/topics/websocket.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [reactive](<https://devfeed.tech/topics/reactive.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [credential-theft](<https://devfeed.tech/tags/credential-theft.md>), [critical-vulnerability](<https://devfeed.tech/tags/critical-vulnerability.md>), [cve-2026-39987](<https://devfeed.tech/tags/cve-2026-39987.md>), [ghsa-2679-6mx9-h9xc](<https://devfeed.tech/tags/ghsa-2679-6mx9-h9xc.md>), [marimo-rce](<https://devfeed.tech/tags/marimo-rce.md>), [marimo-security-issue](<https://devfeed.tech/tags/marimo-security-issue.md>), [marimo-vulnerability](<https://devfeed.tech/tags/marimo-vulnerability.md>), [marimo-websocket-vulnerability](<https://devfeed.tech/tags/marimo-websocket-vulnerability.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [poc](<https://devfeed.tech/tags/poc.md>), [python](<https://devfeed.tech/tags/python.md>), [remote-code-execution](<https://devfeed.tech/tags/remote-code-execution.md>), [unauthenticated-rce](<https://devfeed.tech/tags/unauthenticated-rce.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [websocket](<https://devfeed.tech/tags/websocket.md>)

### AI overview

This article examines the disclosure and rapid exploitation of CVE-2026-39987, a pre-authentication remote code execution vulnerability in the terminal WebSocket endpoint of the open-source marimo Python notebook platform. It reports that attackers obtained interactive shells and carried out credential theft shortly after disclosure, despite no public proof of concept being available.

### Source excerpt

On April 8, 2026, a critical vulnerability was disclosed in marimo, an open-source reactive Python notebook platform. Currently being tracked as GHSA-2679-6mx9-h9xc, it is a pre-authentication remote code execution (RCE) vulnerability in the terminal WebSocket endpoint that allows attackers to obtain a full interactive shell on any exposed marimo instance through a single WebSocket connection - no credentials required. At the time of this writing, a CVE number has yet to be assigned.