2026-06-06 is live. RBL, certificate, and uptime monitoring — now in public beta.

News

CISA Flags Actively Exploited n8n RCE Bug as 24,700 Instances Remain Exposed


The U.S. Cybersecurity and Infrastructure Security Agency (CISA) placed a critical vulnerability affecting the n8n workflow automation platform into its Known Exploited Vulnerabilities (KEV) catalog after observing signs of active misuse.

Logged as CVE-2025-68613 with a CVSS score of 9.9, the flaw is an expression injection issue that can lead to remote code execution. n8n released fixes for the problem in December 2025 in releases 1.120.4, 1.121.1, and 1.122.0. This marks the first n8n-related entry to appear in CISA’s KEV list.

CISA described the weakness as an instance where the platform fails to properly control dynamically managed code resources during workflow expression evaluation, enabling remote execution of code.

According to n8n’s developers, an attacker who is authenticated could exploit this defect to run arbitrary commands under the privileges of the n8n process. Successful exploitation could allow an intruder to fully compromise an instance-viewing or stealing sensitive information, altering workflow logic, or performing operations at the system level.

At this time, CISA has not published technical details about how attackers are exploiting the bug in the wild. However, internet scanning data from the Shadowserver Foundation indicates more than 24,700 publicly reachable n8n instances remain unpatched, with roughly 12,300 located in North America and about 7,800 in Europe as of early February 2026.

The KEV listing follows a disclosure by security firm Pillar Security of two additional critical vulnerabilities in n8n. One of those is tracked as CVE-2026-27577 (CVSS: 9.4) and has been described as an additional exploit vector found within the same workflow expression evaluation component explored in CVE-2025-68613.

Federal Civilian Executive Branch (FCEB) agencies have been directed to remediate affected n8n deployments by March 25, 2026, under the Binding Operational Directive BOD 22-01, which was issued in November 2021.

First published on March 13, 2026.
Last updated on July 15, 2026.