Cyber Security News

Over 100,000 Internet-Exposed n8n Instances Vulnerable to RCE Attacks

A critical remote code execution vulnerability has left over 100,000 n8n workflow automation instances exposed to potential cyberattacks.

The Shadowserver Foundation disclosed that 105,753 vulnerable instances were identified on January 9, 2026, representing nearly half of all detected n8n deployments.

AttributeDetails
CVE IDCVE-2026-21858
CVSS Score10.0 (Critical)
Vulnerability TypeRemote Code Execution (RCE)
Affected Productn8n workflow automation platform

Critical Severity Flaw

The vulnerability, tracked as CVE-2026-21858, carries a maximum CVSS score of 10.0, indicating critical severity.

This remote code execution flaw allows attackers to execute arbitrary code on vulnerable n8n servers without authentication, posing severe risks to organizations using the workflow automation platform.

Of the 230,562 IP addresses running n8n identified during the scan, approximately 46% were found to be vulnerable to exploitation.

The widespread exposure highlights significant security gaps in deployment practices across the n8n user base.

Organizations running n8n instances should immediately verify their deployment security and apply available patches.

The Shadowserver Foundation has made detailed scan data available through its Vulnerable HTTP reports, allowing administrators to check if their systems are affected.

Security teams should prioritize patching this vulnerability given its critical severity rating and the high number of exposed instances.

Network administrators can access the dashboard, tree map view, and IP-specific data through Shadowserver’s reporting infrastructure to identify vulnerable systems within their networks.

The discovery underscores the importance of regular security assessments and timely patch management for internet-facing automation platforms that often have access to sensitive business data and system credentials.

Follow us on Google NewsLinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Divya

Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Recent Posts

AI-Assisted ToxNetV2 Linux Botnet Uses LLM to Generate Shell and SSH Commands

ToxNetV2, an AArch64 Linux peer-to-peer botnet, integrates a large language model into its controller workflow…

7 hours ago

Multi-Agent AI Framework Compromises Government Systems and Steals Thousands of Records

A multi-agent AI framework, utilizing Hermes and OpenClaw agents, was employed to compromise government entities…

8 hours ago

Scammers Impersonate Microsoft to Push Fake Security Scans and Refund Fraud

A cluster of fraudulent websites impersonating Microsoft is using fake “security scans” to pressure victims…

9 hours ago

ASOS Warns Customers of Data Breach Following Credential-Based Account Takeovers

ASOS has started notifying affected customers in the U.S. after detecting unauthorized access to accounts…

9 hours ago

Multiple Zscaler Client Connector Flaws Enable Remote Code Execution

Zscaler has addressed several vulnerabilities in its Client Connector endpoint application that could allow an…

9 hours ago

91 Spring CVEs Impact Over 209,000 Software Components Across the Supply Chain

Broadcom has disclosed 91 Common Vulnerabilities and Exposures (CVEs) affecting the Spring Framework and related…

11 hours ago