logo

Maximum-severity flaw allows full compromise of n8n instances.

ID: 3b956108-88e0-5697-8dfe-22a5626c5a4d

STIX ID: report--3b956108-88e0-5697-8dfe-22a5626c5a4d

Feed Name: The CyberWire

Threat Score
80/100

Date Published: 2026-01-08

Date Updated: 2026-04-23

...
...

This briefing highlights two maximum-severity vulnerabilities — an unauthenticated remote code execution in n8n (CVE-2026-21858) affecting approximately 100,000 instances with no workaround and requiring update to n8n 1.121.0, and an HPE OneView flaw (CVE-2025-37164) that CISA has added to its Known Exploited Vulnerabilities catalog as actively exploited; it also notes the US withdrawal from international cyber expertise organizations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.