Critical Marimo pre-auth RCE flaw now under active exploitation

2026-04-13T13:23:28Z673c3bb5ba3e194b53c178f858cd57eb98e0797802323ddc36e28a4f4d71a713
active-exploitationcredential-theftcriticalincident-responsemarimopatchingpre-authremote-code-executionvulnerabilityzero-day

What happened

BleepingComputer reports a critical pre-authentication remote code execution (RCE) vulnerability in Marimo that is now being actively exploited. Attackers are leveraging the flaw to steal credentials. Organizations running Marimo should assume remote compromise is possible, prioritize immediate mitigation (apply vendor patches or workarounds, isolate affected instances), and monitor for suspicious access and credential theft indicators.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
673c3bb5ba3e194b53c178f858cd57eb98e0797802323ddc36e28a4f4d71a713
Enrichment time
2026-04-13T13:23:28Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.