CVE-2026-39987
Sfruttamento noto · CISA KEV
EPSS 38% (98º percentile).
Data di correzione federale CISA 7 mag · data superata
Vulnerabilità · 123 giorni fa
Un notebook compromesso non è più la fine della storia. In Marimo, gli attacker stanno ora usando un agente LLM per trasformare una singola RCE iniziale in furto di credenziali cloud, accesso a Secrets Manager, accesso SSH ed esfiltrazione da PostgreSQL in circa un’ora, quindi il patching del notebook da solo non rimuove l’accesso già estratto da esso.
Sfruttamento noto · CISA KEV
EPSS 38% (98º percentile).
Data di correzione federale CISA 7 mag · data superata
Sfruttamento noto · CISA KEV
Data di correzione federale CISA 2 apr · data superata
CVSS 8.8 HIGH: in the Linux kernel, the following vulnerability has been resolved: xfrm: esp: avoid in-place decrypt on shared skb frags MSG_SPLICE_PAGES can attach pages from a pipe directly to an skb. EPSS 2% (84º percentile). Patch Microsoft: CBL-Mariner Releases.
CVSS 7.8 HIGH: in the Linux kernel, the following vulnerability has been resolved: rxrpc: Also unshare DATA/RESPONSE packets when… EPSS 2% (82º percentile).
3 fonti che coprono questa storia
Attackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026-39987 Exploit
LLM-driven attackers exploited CVE-2026-39987 on May 10, 2026, to steal credentials and exfiltrate a PostgreSQL database.
This week's Metasploit release focuses heavily on Linux Local Privilege Escalation (LPE) with new modules for the "Dirty Frag" vulnerabilities, identified as CVE-2026-43284 and CVE-2026-43500.
Citrix NetScaler Memory Overread Vulnerability | Outbreak Alert | FortiGuard Labs
Exploitation activity targeting vulnerable Citrix NetScaler ADC and Gateway appliances remains persistent and widespread, with FortiGuard Labs tele...
Part of the PlainSec briefing for 2026-05-29