CISA Flags Actively Exploited n8n RCE Bug as 24,700 Instances Remain Exposed
ID: 6380fc30-43db-564e-8b1c-7a2e9302a78b
STIX ID: report--6380fc30-43db-564e-8b1c-7a2e9302a78b
Feed Name: The Hacker News
Threat Score
CISA has added a critical remote code execution vulnerability in n8n (CVE-2025-68613, CVSS 9.9) to its Known Exploited Vulnerabilities list after evidence of active exploitation. The flaw, an expression injection in n8n's workflow expression evaluation, was patched in December 2025 but Shadowserver reports over 24,700 unpatched instances online; a related critical flaw (CVE-2026-27577) was also disclosed and US federal agencies were ordered to patch by March 25, 2026.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
