The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added an n8n workflow automation platform vulnerability, CVE-2025-68613, to its Known Exploited Vulnerabilities (KEV) catalog and ordered U.S. federal agencies to remediate it by the KEV deadline. The flaw is described as an improper control of dynamically managed code resources issue in n8n’s workflow expression evaluation system that enables authenticated remote code execution (RCE), potentially leading to full instance compromise, workflow tampering, and exposure of sensitive secrets commonly stored in n8n (e.g., API keys, OAuth tokens, database credentials, and CI/CD secrets). Shadowserver reporting cited in coverage indicated a large exposed footprint, with tens of thousands of potentially unpatched n8n instances reachable from the internet.
Separately, researchers disclosed and n8n patched additional critical issues affecting both self-hosted and cloud deployments: CVE-2026-27577 (expression sandbox escape leading to RCE) and CVE-2026-27493 (unauthenticated expression evaluation via Form nodes that can enable expression injection and, when chained with a sandbox escape, RCE). These issues were reported as fixed in n8n versions 2.10.1, 2.9.3, and 1.123.22, and include an exploitation path involving public-by-design form endpoints (e.g., “Contact Us” forms) to inject payloads. While distinct from the KEV-listed CVE, the disclosures reinforce that n8n’s expression evaluation and workflow permissions are high-risk areas; mitigations discussed include rapid patching and restricting workflow creation/editing to fully trusted users when immediate upgrades are not possible.

See which actors are running it and whether you're in range.
6 events from the most recent confirmed update back to the earliest known activity.
Public proof-of-concept exploit code for CVE-2025-68613 was released by SecureLayer7 before CISA's KEV action. The publication provided technical details that could facilitate exploitation of unpatched n8n instances.
Following the KEV addition, CISA ordered Federal Civilian Executive Branch agencies to remediate CVE-2025-68613 under Binding Operational Directive 22-01. Agencies were given a deadline of 2026-03-25, and CISA urged all defenders to patch or apply temporary hardening measures immediately.
On 2026-03-11, CISA added the n8n remote code execution flaw CVE-2025-68613 to its Known Exploited Vulnerabilities catalog after confirming active exploitation in the wild. The KEV entry directed organizations to apply vendor mitigations or discontinue use if mitigations were unavailable.
By early February 2026, Shadowserver data showed that more than 24,700 unpatched n8n instances remained exposed online. Other reporting around the same period described the exposed population as exceeding 40,000, indicating widespread lag in patching.
As of 2025-12-22, Censys reported 103,476 potentially vulnerable internet-exposed n8n instances. Many of the exposed systems were located in the United States, Germany, and France.
In December 2025, n8n disclosed and fixed the authenticated remote code execution flaw CVE-2025-68613 in patched releases 1.120.4, 1.121.1, and 1.122.0. The bug affected the platform's workflow expression evaluation system and could lead to full instance compromise.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
8 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcesecurityaffairs.com
Open sourcethehackernews.com
Open sourcetheregister.com
Open sourcego.theregister.com
Open sourcebleepingcomputer.com
Open sourcegithub.com
Open sourcecyber.gc.ca
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.