<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>WildforTech Security Advisories — Marimo</title><description>Actively exploited vulnerabilities affecting Marimo products.</description><link>https://wildfortech.com</link><atom:link href="https://wildfortech.com/security/vendor/marimo.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-39987 — Marimo Remote Code Execution Vulnerability</title><link>https://wildfortech.com/security#CVE-2026-39987</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2026-39987</guid><description>This vulnerability in Marimo allows an unauthenticated attacker to execute arbitrary system commands without any prior login or credentials — a pre-authorization remote code execution flaw. In practice, this means anyone who can reach a Marimo instance over the network could gain shell-level control of the underlying system, potentially leading to full server compromise, data exfiltration, or use as a foothold for further attacks. No user interaction or account is required, making this especially dangerous for internet-exposed deployments.</description><pubDate>Thu, 23 Apr 2026 00:00:00 GMT</pubDate><category>Marimo</category><category>Marimo</category></item></channel></rss>