Related Threat Clusters
-
Critical n8n Vulnerability Enables Arbitrary Command Execution
A critical vulnerability in the n8n workflow automation platform, tracked as CVE-2025-68668, allows authenticated users to execute arbitrary system commands on affected servers. With a CVSS score of 9.9, this flaw…
19 articles · Updated January 6, 2026 -
Critical RCE Vulnerability in n8n Affects Over 100K Servers
A critical remote code execution vulnerability (CVE-2025-68613) in the n8n workflow automation platform has been disclosed, potentially impacting over 100,000 servers, primarily in the United States. The flaw, which has…
4 articles · Updated December 24, 2025 -
Critical n8n RCE Vulnerability Exploit Code Released
Security researchers have released proof-of-concept exploit code for a critical remote code execution vulnerability affecting n8n. This vulnerability poses significant risks to users of the platform, enabling potential…
2 articles · Updated December 23, 2025 -
Iranian APT Groups Target Israeli Organizations with Modular C2 Frameworks
In 2026, Iranian APT groups, notably Cavern Manticore and OilRig, have intensified cyber operations against Israeli organizations, primarily in the IT and government sectors. Cavern Manticore employs a modular…
10 articles · Updated July 6, 2026 -
Critical RCE Vulnerability in Marimo Exploited Within 10 Hours of Disclosure
On April 8, 2026, a critical pre-authenticated remote code execution vulnerability (CVE-2026-39987) was disclosed in Marimo, an open-source Python notebook platform. The flaw allows unauthenticated attackers to gain a…
2 articles · Updated June 9, 2026 -
Langflow IDOR Exploit and Critical Vulnerabilities Targeting AI Platforms
A moderate-scored IDOR vulnerability (CVE-2026-55255) in Langflow has been actively exploited since June 25, 2026, allowing attackers to access and execute flows belonging to other users. This exploit leverages a…
5 articles · Updated July 25, 2026 -
Exploitation of N8n Flaw and Linux Vulnerabilities Highlight Cybersecurity Risks
Recent reports indicate that a vulnerability in N8n has been actively exploited, posing significant risks to users. Additionally, researchers from Qualys have identified nine vulnerabilities in the Linux AppArmor, which…
2 articles · Updated March 13, 2026 -
Critical n8n RCE Vulnerability Requires Immediate Update
n8n has issued a critical security alert regarding a remote code execution (RCE) vulnerability identified as CVE-2026-21877. Users are urged to update to version 1.121.3 to mitigate potential attacks. This vulnerability…
5 articles · Updated January 7, 2026 -
Critical n8n Vulnerability Exposes 103,000+ Instances to RCE Attacks
A critical remote code execution vulnerability, tracked as CVE-2025-68613, has been identified in the n8n automation platform, affecting over 103,000 instances globally. The flaw allows authenticated attackers to…
4 articles · Updated December 23, 2025 -
n8n Sandbox Escape Vulnerability Allows OS Command Execution
On July 22, 2026, n8n released a patch for a high-severity sandbox escape vulnerability (GHSA-gv7g-jm28-cr3m) rated 8.7 on CVSS 4.0. This flaw allows authenticated users to execute operating system commands via crafted…
3 articles · Updated July 30, 2026
Recent Intelligence Reports
- vulncheck.com: VulnCheck Advisory: n8n before 1.123.73 Remote Code Execution via Git Node external site — www.vulncheck.com · September 3, 2026
- CVE-2026-77084 - Exploits & Severity — Feedly · August 20, 2026
- Leaked n8n API Tokens Exposed Live Instances to Credential Theft — Thehackernews · August 5, 2026
- n8n Security: How Leaked API Keys Expose Your Encryption Key — Blog.Gitguardian · August 4, 2026
- BleepingComputer summarised the finding — www.bleepingcomputer.com · August 2, 2026
- DeepSeek Became the Attack Engine Because It Had the Fewest Guardrails — Forkast.News · August 1, 2026
- Unit 42 Ties DeepSeek Agent to 460+ Autonomous Hack Attempts — Aiweekly.Co · August 1, 2026
- DeepSeek Ran Autonomous Cyberattacks That Claude and OpenAI Safety Controls Blocked — Techtimes · August 1, 2026