German security advisories from dCERT reported multiple vulnerabilities affecting n8n, the workflow automation and orchestration platform. The notices identify separate advisories, 2026-0860 and 2026-1228, indicating that more than one set of security issues has been documented for the product.
The available advisory metadata does not include technical synopses, affected versions, or mitigation details, but the repeated disclosures signal an ongoing security concern for organizations using n8n. Security teams should review the referenced dCERT advisories, determine whether deployed n8n instances are affected, and prioritize vendor patches or other recommended mitigations as details become available.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
dCERT issued advisory 2026-1560 for an n8n vulnerability that allows information disclosure. The reference indicates a new advisory publication but provides no further technical details or remediation information.
dCERT issued a third advisory, 2026-1490, covering multiple vulnerabilities affecting n8n. The reference indicates a new advisory publication but does not provide further technical details or remediation information.
dCERT issued a second advisory, 2026-1228, for multiple vulnerabilities in n8n. The reference indicates a new advisory publication but does not include additional specifics about the flaws or remediation.
dCERT issued advisory 2026-0860 covering multiple vulnerabilities affecting n8n. No further technical details are provided in the reference content.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
dcert.de
Open sourcedcert.de
Open sourcedcert.de
Open sourcedcert.de
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.