CVE-2026-39987
Known exploited · CISA KEV
EPSS 99% (100th percentile).
CISA federal remediation date May 7
Vulnerabilities & Exploits · Credential Theft
A notebook RCE is not just a code-execution bug here. It gives attackers a fast path to turn a trusted demo environment into a credential-theft and malware-delivery point, and patching the notebook does not undo anything already pulled from the host.
Sysdig says exploitation of CVE-2026-39987 began less than 10 hours after technical details were public. The campaign used Hugging Face Spaces to host a typosquatted Space that delivered a dropper and a new NKAbuse variant, with the activity starting on April 12 and targeting Marimo users through the /terminal/ws attack surface.
The risk now is speed and trust. AI hosting platforms can be repurposed as clean-looking distribution points almost immediately, which shortens the time between disclosure and weaponized delivery for anyone running exposed Marimo instances.
1 source · Apr 16
Known exploited · CISA KEV
EPSS 99% (100th percentile).
CISA federal remediation date May 7
BleepingComputer
Hackers exploit Marimo flaw to deploy NKAbuse malware from Hugging Face
Hackers are exploiting a critical vulnerability in Marimo reactive Python notebook to deploy a new variant of NKAbuse malware hosted on Hugging Face Spaces.
originalPart of the PlainSec briefing for 2026-04-29
Every edition of this story: Marimo Zero-Day Turns AI Demo Hosting Into Malware Delivery