logo

Researchers rush to warn defenders of max-severity defect in n8n

ID: e41aa7e2-ab00-58fd-af4e-4686fa7500cb

STIX ID: report--e41aa7e2-ab00-58fd-af4e-4686fa7500cb

Feed Name: CyberScoop

Threat Score
75/100

Date Published: 2026-01-07

Date Updated: 2026-04-21

Author: Matt Kapko

...
...

A critical, unauthenticated remote-code-execution vulnerability (CVE-2026-21858, dubbed “ni8mare”) was disclosed in the n8n automation platform affecting ~100,000 servers. The vendor released a patch (update to v1.121.1 or later) after researchers published a working proof-of-concept; researchers have not observed confirmed in-the-wild exploitation but note increased scanning and emphasize the high risk due to n8n’s access to tokens, credentials and business-critical workflows.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.