Hackers Exploit CVE-2026-39987 RCE Flaw in Python Data Tool Marimo
Marimo is an interactive computing environment for Python data analysis. The critical vulnerability, tracked as CVE-2026-39987, allows unauthenticated attackers to remotely execute code through a WebSocket endpoint and obtain a system shell, putting corporate databases, API keys and cloud credentials at risk.
The flaw was exploited shortly after it was disclosed. As of April 17, 2026, attackers had used Hugging Face to distribute NKAbuse malware and deployed AI agents to infiltrate internal databases. Related attacks also involved APT41, which targeted four major cloud environments to harvest credentials and tokens.
All Coverage
4 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →