# Sysdig details rapid Marimo exploit path to AWS-backed SSH access

_Tuesday, September 15, 2026 at 7:52 AM EDT · Security, Infrastructure · Latest · Tier 1 — Major_

![Sysdig details rapid Marimo exploit path to AWS-backed SSH access — Primary](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjzWVpv5OsfVGAYPz4or_uMgVNDXTSzyXpTB8XLtCFHdzk9IliH8Aydez_Zo9hDGSj7__A0cFwnjKUpRWn5nn4CSd5wlaIJ1-BpU29tUyeh3pC63H_kXIn9ANQna1FBENp-td6TCC6z50ZEcAeNjAZMA-tIA9_x9nYrlHqbnJOijQpbeHsQmW5tKMczy4ek/s1700-nu-rw-lo-l85-e365/marimo%20%281%29.jpg)

Sysdig reported that a threat actor exploited CVE-2026-39987, a pre-authenticated remote-code-execution flaw in Marimo, then reached an SSH bastion host in eight seconds. The reported chain used credentials harvested from the compromised instance to call AWS Secrets Manager, retrieve a private key and authenticate to the bastion. Sysdig said the flaw affects all Marimo versions and entered active exploitation within hours of public disclosure. The operator issued more than 850 commands during a nine-hour session, according to the report.

## Sources

- [The Hacker News](https://thehackernews.com/2026/09/human-attacker-exploits-marimo-rce.html)

---
Canonical: https://techandbusiness.org/newswire/mpke-q_cRiRHgDgB86v7bp
Retrieved: 2026-09-15T16:45:14.780Z
Publisher: Tech & Business (techandbusiness.org)
