Tuesday, August 25, 2026

Over 100,000 Internet-Exposed n8n Instances Vulnerable to RCE Attacks

A critical remote code execution vulnerability has left over 100,000 n8n workflow automation instances exposed to potential cyberattacks.

The Shadowserver Foundation disclosed that 105,753 vulnerable instances were identified on January 9, 2026, representing nearly half of all detected n8n deployments.

AttributeDetails
CVE IDCVE-2026-21858
CVSS Score10.0 (Critical)
Vulnerability TypeRemote Code Execution (RCE)
Affected Productn8n workflow automation platform

Critical Severity Flaw

The vulnerability, tracked as CVE-2026-21858, carries a maximum CVSS score of 10.0, indicating critical severity.

This remote code execution flaw allows attackers to execute arbitrary code on vulnerable n8n servers without authentication, posing severe risks to organizations using the workflow automation platform.

Of the 230,562 IP addresses running n8n identified during the scan, approximately 46% were found to be vulnerable to exploitation.

The widespread exposure highlights significant security gaps in deployment practices across the n8n user base.

Organizations running n8n instances should immediately verify their deployment security and apply available patches.

The Shadowserver Foundation has made detailed scan data available through its Vulnerable HTTP reports, allowing administrators to check if their systems are affected.

Security teams should prioritize patching this vulnerability given its critical severity rating and the high number of exposed instances.

Network administrators can access the dashboard, tree map view, and IP-specific data through Shadowserver’s reporting infrastructure to identify vulnerable systems within their networks.

The discovery underscores the importance of regular security assessments and timely patch management for internet-facing automation platforms that often have access to sensitive business data and system credentials.

Follow us on Google NewsLinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

AI-Assisted ToxNetV2 Linux Botnet Uses LLM to Generate Shell and SSH Commands

ToxNetV2, an AArch64 Linux peer-to-peer botnet, integrates a large...

Multi-Agent AI Framework Compromises Government Systems and Steals Thousands of Records

A multi-agent AI framework, utilizing Hermes and OpenClaw agents,...

Scammers Impersonate Microsoft to Push Fake Security Scans and Refund Fraud

A cluster of fraudulent websites impersonating Microsoft is using...

Multiple Zscaler Client Connector Flaws Enable Remote Code Execution

Zscaler has addressed several vulnerabilities in its Client Connector...

91 Spring CVEs Impact Over 209,000 Software Components Across the Supply Chain

Broadcom has disclosed 91 Common Vulnerabilities and Exposures (CVEs)...

PavinLoader Uses ClickFix and Fake Downloads to Deploy Amatera Stealer via Blockchain C2

PavinLoader, a multi-stage .NET malware loader, operating across ClickFix,...

Anthropic Expands Claude MCP Security With Enterprise-Managed Identity Controls

Anthropic has expanded Claude Enterprise’s Model Context Protocol (MCP)...

Related Articles

Recent News