Advertisement
n8n RCE via Expression Sandbox Escape — Mitigation Guide
Authenticated workflow editors in n8n can execute arbitrary OS commands via a sandbox escape. Update to versions 2.31.5 or 2.32.1 to mitigate this risk.
n8n Token Exchange Flaw: Impersonation via `sub` Claim Bypass
A critical token exchange vulnerability in n8n Enterprise allows attackers to impersonate users by leveraging `sub` claim matching across multiple external issuers…
Ivanti, Fortinet, and n8n Disclose Critical RCE and Auth Bypass Flaws
Ivanti, Fortinet, n8n, and SAP release urgent security patches for critical vulnerabilities including CVE-2026-5444 and CVE-2026-8043. Update systems now.
Abused n8n Webhooks Facilitate Automated Malware Delivery Since 2025
Threat actors are weaponizing n8n AI workflow automation webhooks to bypass email filters and distribute malware in persistent phishing campaigns.
N8n Flaw Exploitation, Slopoly Malware, AppArmor LPE: Key Threats
Analysis of recent cybersecurity threats: actively exploited N8n flaw, Slopoly malware, Linux AppArmor root privilege vulnerability, and Telus Digital breach.
n8n RCE via CVE-2025-68613 — CISA Flags Active Exploitation
CISA adds CVE-2025-68613 to its KEV catalog after reports of active exploitation against n8n workflow automation instances. Patch now to prevent RCE.
Advertisement
CVE-2025-68613: n8n Improper Code Control — Actively Exploited
CISA adds CVE-2025-68613, an n8n vulnerability involving improper control of dynamically-managed code, to its KEV Catalog due to active exploitation.
n8n RCE Vulnerabilities CVE-2026-27577 and CVE-2026-27493 - Patch Now
Critical vulnerabilities in the n8n workflow automation platform allow unauthenticated remote code execution and sandbox escapes. Update instances immediately.