Maximum-severity flaw allows full compromise of n8n instances.
ID: 3b956108-88e0-5697-8dfe-22a5626c5a4d
STIX ID: report--3b956108-88e0-5697-8dfe-22a5626c5a4d
Feed Name: The CyberWire
Threat Score
This briefing highlights two maximum-severity vulnerabilities — an unauthenticated remote code execution in n8n (CVE-2026-21858) affecting approximately 100,000 instances with no workaround and requiring update to n8n 1.121.0, and an HPE OneView flaw (CVE-2025-37164) that CISA has added to its Known Exploited Vulnerabilities catalog as actively exploited; it also notes the US withdrawal from international cyber expertise organizations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
