🔴
CISA KEV Alert — Active Real-World Exploitation Confirmed
This vulnerability is in the CISA Known Exploited Vulnerabilities catalog and is being actively exploited right now.
Marimo Pre-Authorization Remote Code Execution (CVE-2026-39987) | MSSP Advisory
Critical🔴 KEV ALERT
DateMay 6, 2026
CVECVE-2026-39987
CVSS Score9.8
Affectedmarimo
📋Executive Summary
CISA flagged CVE-2026-39987 in Marimo, a pre-authorization remote code execution flaw that gives attackers direct shell access without authentication. This creates immediate exposure for any MSSP or client environment running Marimo applications.
⚠️Why It Matters for MSSPs
Your stack could contain Marimo instances you are not tracking, and compromised Marimo servers provide direct system access that bypasses most monitoring tools. Client environments using Marimo for data analysis or visualization become instant footholds for lateral movement, and you own the advisory obligation to flag this risk.
✅Recommended Action
Scan all managed environments for Marimo installations within 24 hours and immediately isolate any discovered instances. Contact affected clients with specific remediation timelines and document your advisory communication for contract compliance.
🔒Get your first advisory free →
Partner content — get access free
The recommended action is included in your white-labeled advisory — ready to send to clients under your name.
🏷️Threat Category
Zero-Day
Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.