logo

CISA warns max-severity n8n bug is being exploited in the wild

ID: c175c4f3-5813-5440-aa83-45a918369db4

STIX ID: report--c175c4f3-5813-5440-aa83-45a918369db4

Feed Name: The Register (Security)

Threat Score
90/100

Date Published: 2026-03-12

Date Updated: 2026-04-26

Author: Connor Jones

...
...

CISA confirmed active exploitation of a critical remote code execution vulnerability in the n8n workflow automation platform (CVE-2025-68613, CVSS 9.9), affecting a large portion of its user base; n8n released patches (v1.122.0) and subsequent related high-severity flaws (including CVE-2026-21858 and CVE-2026-25049) were disclosed, and federal agencies have been urged to patch immediately to avoid full instance compromise or supply-chain impact.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.