INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Human Attacker Exploits Marimo RCE to Reach SSH Bastion

| 2026-09-08 16:59 MEDIUM HIGH EXPLOITED VULNERABILITY MALWARE & BOTNETS
Executive Summary
AI-generated
On September 15, 2026, a human attacker exploited the CVE-2026-39987 vulnerability in Marimo to gain SSH access to an Amazon Web Services (AWS) bastion host within eight seconds. The attack chain leveraged the pre-authenticated remote code execution flaw to obtain credentials from a compromised instance and then used those credentials to authenticate to the bastion host. Over the course of nine hours, the attacker issued over 850 interactive commands without using recognizable publicly available tooling, instead relying on custom Python scripts written and debugged by hand. The attack highlights the speed and tradecraft of skilled human attackers who can outperform AI-assisted attacks in exploiting vulnerabilities.
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2021-33044, CVE-2026-39987 and treat internet-facing systems that were not patched in time as potentially compromised until verified.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

ay•••••.net
hu•••••.io
so•••••.net
20.198.•••.•••
188.245.•••.•••
47.250.•••.•••
172.236.•••.•••
420c78••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
f90c8b••••••••••••••••••••••••••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Operation CameraSwarmOperation CameraSwarm CVE-2021-33044CVE-2021-33044 CVE-2026-39987CVE-2026-39987 CVE-2021-33045CVE-2021-33045
Target & Sectors
Global Scope
Incident Timeline
‎February 2026
A February 2026 open directory linked by wallet reuse revealed Meterpreter deployment capabilities.
‎May 7, 2026
Threat actors used the Marimo RCE exploit to target a system with CVE-2026-39987, which was listed on CISA's Known Exploited Vulnerabilities catalog.
attribution CVE-2026-39987
attribution Known Exploited
tactic T1588.006 - Vulnerabilities
attribution KEV
‎2026/09/08
A human attacker exploited the CVE-2026-39987 Marimo RCE vulnerability to reach an SSH bastion host in just eight seconds.
infrastructure 3,562 Servers
organisation Redis
infrastructure 12,966 hosts
infrastructure Windows
data_breach 147 files
organisation SSH
infrastructure Linux
infrastructure 2.8.17
infrastructure 7.2.0
organisation Ubuntu
organisation WordPress
infrastructure 9.3
infrastructure 0.20.4
infrastructure 0.23.0
infrastructure 47.250.92
infrastructure 34.166.99
infrastructure 20.198.10
organisation HTTPS
organisation XML-RPC
organisation CVE-2021-33045
organisation Operation CameraSwarm
organisation Dahua IP
infrastructure 14,000 Dahua IP cameras
organisation Reaches SSH Bastion
organisation ATA
organisation WebSocket
organisation VPS
organisation GPU
organisation AWS
organisation GCP
‎September 11
Threat actors exploited CVE-2026-39987, a pre-authentication remote code execution flaw in the Marimo notebook platform.
vulnerability CVE-2026-39987
tactic Remote Code Execution
organisation Sysdig
organisation Threat Research Team
organisation CVE-2026
‎Sep 15, 2026
Threat actors successfully exploited a remote code execution (RCE) vulnerability in the Marimo system to gain unauthorized access.
Tactical Metrics
Metrics
infrastructure
3,562
Servers
Metrics
infrastructure
‎Windows
Affected Product
Metrics
data_breach
147
Files
Metrics
infrastructure
‎Linux
Affected Product
Metrics
infrastructure
‎2.8.17
Software Version
Metrics
infrastructure
‎7.2.0
Software Version
Metrics
infrastructure
12,966
Hosts
Metrics
infrastructure
‎9.3
Software Version
Metrics
infrastructure
‎47.250.92
Software Version
Metrics
infrastructure
‎34.166.99
Software Version
Metrics
infrastructure
‎20.198.10
Software Version
Metrics
infrastructure
14,000
Dahua Ip Cameras
Metrics
infrastructure
‎0.20.4
Software Version
Metrics
infrastructure
‎0.23.0
Software Version
Intelligence Sources