logo

100,000+ n8n Instances Exposed to Internet Vulnerable to RCE Attacks

ID: f53c7071-30b3-5887-bdd1-f0b628956c41

STIX ID: report--f53c7071-30b3-5887-bdd1-f0b628956c41

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-01-13

Date Updated: 2026-04-21

Author: Abinaya

...
...

A critical unauthenticated RCE (CVE-2026-21858, CVSS 10.0) in n8n’s webhook handling affects ~105,753 internet-exposed instances (versions 1.65.0–1.120.x), allowing full instance takeover and data exposure; immediate patching to n8n 1.121.0, network access restrictions, and monitoring are strongly recommended.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.