🔴
CISA KEV Alert — Active Real-World Exploitation Confirmed
This vulnerability is in the CISA Known Exploited Vulnerabilities catalog and is being actively exploited right now.

Marimo Pre-Authorization Remote Code Execution (CVE-2026-39987) | MSSP Advisory

Critical🔴 KEV ALERT
DateMay 6, 2026
CVECVE-2026-39987
CVSS Score9.8
Affectedmarimo
📋Executive Summary
CISA flagged CVE-2026-39987 in Marimo, a pre-authorization remote code execution flaw that gives attackers direct shell access without authentication. This creates immediate exposure for any MSSP or client environment running Marimo applications.
⚠️Why It Matters for MSSPs
Your stack could contain Marimo instances you are not tracking, and compromised Marimo servers provide direct system access that bypasses most monitoring tools. Client environments using Marimo for data analysis or visualization become instant footholds for lateral movement, and you own the advisory obligation to flag this risk.
Recommended Action
Scan all managed environments for Marimo installations within 24 hours and immediately isolate any discovered instances. Contact affected clients with specific remediation timelines and document your advisory communication for contract compliance.
🔒
Partner content — get access free
The recommended action is included in your white-labeled advisory — ready to send to clients under your name.
Get your first advisory free →
🏷️Threat Category
Zero-Day

Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.