Vulnerabilities · 123 days ago

Marimo Foothold Now Moves Faster Than Patching

A compromised notebook is no longer the end of the story. In Marimo, attackers are now using an LLM agent to turn one initial RCE into cloud credential theft, Secrets Manager access, SSH access, and PostgreSQL exfiltration in about an hour, so patching the notebook alone does not remove the access already pulled out of it.

Sysdig says the attack hit an internet-reachable Marimo notebook through CVE-2026-39987, which affects all versions up to and including 0.20.4 and is fixed in 0.23.0. The attacker extracted two cloud credentials from the host, replayed them to retrieve an SSH private key from AWS Secrets Manager, then used that key for short SSH sessions against a bastion and pulled the schema and full contents of an internal PostgreSQL database. In the same cycle, Rapid7 added Metasploit modules for the Dirty Frag Linux LPEs, plus scanners for Citrix NetScaler and Ollama, lowering the bar on adjacent compromise paths.

The practical risk is that a public notebook can now become an automated credential-harvesting workflow, not just a single vulnerable app. If cloud keys, Secrets Manager, or bastion access are reachable from that host, the compromise can extend into downstream systems after the original flaw is fixed.

CVE-2026-39987

NVD KEV

Known exploited · CISA KEV

EPSS 38% (98th percentile).

CISA federal remediation date May 7 · date passed

CVE-2026-3055

NVD KEV

Known exploited · CISA KEV

CISA federal remediation date Apr 2 · date passed

CVE-2026-43284

NVD KEV

CVSS 8.8 HIGH: in the Linux kernel, the following vulnerability has been resolved: xfrm: esp: avoid in-place decrypt on shared skb frags MSG_SPLICE_PAGES can attach pages from a pipe directly to an skb. EPSS 2% (84th percentile). Microsoft patch: CBL-Mariner Releases.

CVE-2026-43500

NVD KEV

CVSS 7.8 HIGH: in the Linux kernel, the following vulnerability has been resolved: rxrpc: Also unshare DATA/RESPONSE packets when… EPSS 2% (82nd percentile).

Timeline

Sources

3 sources covering this story

Entities

Vendor digest: Citrix

Part of the PlainSec briefing for 2026-05-29

Editions

Related stories