A critical remote code execution vulnerability has left over 100,000 n8n workflow automation instances exposed to potential cyberattacks.
The Shadowserver Foundation disclosed that 105,753 vulnerable instances were identified on January 9, 2026, representing nearly half of all detected n8n deployments.
| Attribute | Details |
|---|---|
| CVE ID | CVE-2026-21858 |
| CVSS Score | 10.0 (Critical) |
| Vulnerability Type | Remote Code Execution (RCE) |
| Affected Product | n8n workflow automation platform |
Critical Severity Flaw
The vulnerability, tracked as CVE-2026-21858, carries a maximum CVSS score of 10.0, indicating critical severity.
This remote code execution flaw allows attackers to execute arbitrary code on vulnerable n8n servers without authentication, posing severe risks to organizations using the workflow automation platform.
Of the 230,562 IP addresses running n8n identified during the scan, approximately 46% were found to be vulnerable to exploitation.
The widespread exposure highlights significant security gaps in deployment practices across the n8n user base.
Organizations running n8n instances should immediately verify their deployment security and apply available patches.
The Shadowserver Foundation has made detailed scan data available through its Vulnerable HTTP reports, allowing administrators to check if their systems are affected.
Security teams should prioritize patching this vulnerability given its critical severity rating and the high number of exposed instances.
Network administrators can access the dashboard, tree map view, and IP-specific data through Shadowserver’s reporting infrastructure to identify vulnerable systems within their networks.
The discovery underscores the importance of regular security assessments and timely patch management for internet-facing automation platforms that often have access to sensitive business data and system credentials.
Follow us on Google News, LinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.





