Sploitus Critical RCE Vulnerability in n8n Disclosed (CVE-2025-68613)
Article Content
- •CVE-2025-68613 allows RCE in n8n with CVSS score of 9.9-10.0.
- •Authenticated users can exploit this vulnerability to execute arbitrary code.
- •Publicly available PoC and detection tools increase risk of exploitation.
CVE-2025-68613 is a critical remote code execution (RCE) vulnerability found in n8n, an open-source workflow automation platform. This flaw allows authenticated users to execute arbitrary code on the server, risking full system compromise. The CVSS score for this vulnerability is 9.9 to 10.0, indicating its severity. The vulnerability requires low-privilege authentication, making it particularly dangerous as it can be exploited by users with minimal access. A proof-of-concept (PoC) exploit is publicly available, and tools for detecting vulnerable instances have been released. n8n is widely used for integrating APIs and automating business processes, increasing the potential impact of this vulnerability. The vulnerability was disclosed on September 14, 2026, and is currently under active exploitation, having been added to the CISA KEV list on March 11, 2026.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2016-4437 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical GitLab CVE-2026-85706 Exploited; Microsoft Issues Record 974 Patches A critical CVE-2026-85706 path-traversal vulnerability in GitLab (CVSS 10.0) was exploited in the wild just hours after its disclosure on September 12, 2026. Microsoft released its largest-ever patch batch, addressing 974 vulnerabilities, including several actively exploited Windows flaws. The GitLab flaw allows…