Mark RadarMARK RADAR
About
EN
Sign in

Hackers Exploit CVE-2026-39987 RCE Flaw in Python Data Tool Marimo

4 reports · First detected 2026-04-14 · Last active 2026-06-02

Marimo is an interactive computing environment for Python data analysis. The critical vulnerability, tracked as CVE-2026-39987, allows unauthenticated attackers to remotely execute code through a WebSocket endpoint and obtain a system shell, putting corporate databases, API keys and cloud credentials at risk.

The flaw was exploited shortly after it was disclosed. As of April 17, 2026, attackers had used Hugging Face to distribute NKAbuse malware and deployed AI agents to infiltrate internal databases. Related attacks also involved APT41, which targeted four major cloud environments to harvest credentials and tokens.

All Coverage

4 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR

If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →

All times are in Taipei time (GMT+8)