Rishi[verified]@rxeriumActive Exploitation
The post confirms that CVE-2026-39987, a pre‑authentication RCE via WebSocket, is actively being exploited in the wild, offers a scanning resource, and references the patch version and advisory.
NullSecurityX[verified]@NullSecurityXDisclosure
The post reveals a pre‑authentication WebSocket‑based RCE in marimo that yields a root shell, but does not mention a PoC link, exploit code, or active attacks, and no patch or mitigation is discussed.
秋风[verified]@q1uf3ngPatch
The tweet references CVE-2026-39987 and links to a vendor security release that provides patch details and technical information, but no PoC, exploit code, or active exploitation is mentioned.
yousukezan[verified]@yousukezanActive Exploitation
CVE-2026-39987 in Marimo caused unauthenticated remote code execution actively exploited within 10 hours of disclosure, and a patch (v0.23.0) is available for the vulnerability.
OrcaRouter 🐳[verified]@OrcaRouterActive Exploitation
The tweet reports that the marimo CVE‑2026‑39987 was used in the wild, enabling an AI agent to extract a complete internal database within two minutes.
Vivek | Cybersecurity[verified]@VivekIntelGeneral
The tweet references an article about attackers using an LLM agent after exploiting Marimo CVE-2026-39987, but provides no concrete technical, PoC, exploit, or mitigation details.
Nicolas Krassas[verified]@DinosnActive Exploitation
The article reports that the Marimo RCE vulnerability (CVE‑2026‑39987) was actively exploited within ten hours of its disclosure, but it does not provide a PoC, patch information, or false‑positive clarification.
Nicolas Krassas[verified]@DinosnActive Exploitation
Attackers reportedly used an LLM agent for post‑exploitation after exploiting Marimo CVE‑2026‑39987, indicating real‑world exploitation of the vulnerability.