Critical Marimo pre-auth RCE flaw now under active exploitation
2026-04-13T13:23:28Z•673c3bb5ba3e194b53c178f858cd57eb98e0797802323ddc36e28a4f4d71a713
active-exploitationcredential-theftcriticalincident-responsemarimopatchingpre-authremote-code-executionvulnerabilityzero-day
What happened
BleepingComputer reports a critical pre-authentication remote code execution (RCE) vulnerability in Marimo that is now being actively exploited. Attackers are leveraging the flaw to steal credentials. Organizations running Marimo should assume remote compromise is possible, prioritize immediate mitigation (apply vendor patches or workarounds, isolate affected instances), and monitor for suspicious access and credential theft indicators.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 673c3bb5ba3e194b53c178f858cd57eb98e0797802323ddc36e28a4f4d71a713
- Enrichment time
- 2026-04-13T13:23:28Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.