INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

N8n RCE Vulnerability Exploited in the Wild

| 2026-03-12 13:34 CRITICAL HIGH
Executive Summary AI-generated
The US Cybersecurity and Infrastructure Security Agency has confirmed that hackers are exploiting a max-severity remote code execution vulnerability in workflow automation platform n8n. The bug, which was first disclosed in December, affects roughly 230,000 active users of the platform, with more than 103,000 appearing vulnerable to exploitation. This could lead to simple data theft or full-blown supply chain compromise if not patched promptly.
Technical Mitigations AI-generated
* Ensure all federal civilian executive branch (FCEB) agencies run the latest version of n8n, specifically v1.122.0 or later, to patch CVE-2025-68613. * Implement robust access controls and authentication mechanisms for workflow automation tasks to prevent unauthorized access to sensitive data and system-level operations. * Regularly monitor and update workflows and configurations to ensure they are not vulnerable to exploitation of the max-severity n8n bug.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2025-68613CVE-2025-68613 CVE-2026-25049CVE-2026-25049 CVE-2026-21858CVE-2026-21858 CVE-2026-27577CVE-2026-27577
Target & Sectors
Global Scope
Incident Timeline
November 2021
Threat actors used a max-severity n8n vulnerability to exploit the N8N instance of FCEB agencies by November 2021.
infrastructure N8N
attribution FCEB
attribution Federal Civilian Executive Branch
December 22, 2025
Threat actors exploited a max-severity n8n vulnerability in the wild.
organisation Censys
general_metric 103,476 vulnerable instances
December 2025
Researchers warned that a critical vulnerability in the n8n workflow automation platform, CVE-2025-68613, allowed attackers to achieve arbitrary code execution under certain circumstances.
infrastructure N8N
vulnerability CVE-2025-68613
organisation CVE-2025
infrastructure 1.120.4
infrastructure 1.121.1
infrastructure 1.122.0
early February 2026
Threat actors used a max-severity n8n bug to exploit unpatched instances in North America and Europe.
general_metric 24,700 Instances
source_region EUROPE
source_region NORTH_AMERICA
organisation the Shadowserver Foundation
general_metric 12,300 instances
general_metric 7,800 America
Mar 12, 2026
Threat actors used a max-severity n8n vulnerability to exploit the incident.
2026-03-12
N8n's advisory warns that an authenticated attacker could use the flaw to execute arbitrary code with the privileges of the n8n process.
infrastructure N8N
organisation Users
organisation KEV
organisation Pillar Security
organisation Resecurity
victims 230,000 active users
victims 103,000 users
organisation RCE
organisation CVE-2025-68613
infrastructure 1.120.4
infrastructure 1.121.1
infrastructure 1.122.0
organisation npm
infrastructure 57,000 downloads
organisation CVE-2026-25049
organisation CVE
March 25, 2026
Threat actors used a max-severity n8n vulnerability to exploit the N8N instance in Federal Civilian Executive Branch (FCEB) agencies.
infrastructure N8N
attribution FCEB
attribution Federal Civilian Executive Branch
March 25
FCEB agencies are advised to ensure they have the latest version of Safe 2023.
attribution FCEB
Tactical Metrics
Metrics
infrastructure
​N8N
Affected Product
Metrics
infrastructure
​1.120.4
Software Version
Metrics
infrastructure
​1.121.1
Software Version
Metrics
infrastructure
​1.122.0
Software Version
Metrics
infrastructure
57,000
Downloads
Metrics
victims
230,000
Active Users
Metrics
victims
103,000
Users
Intelligence Sources
The Register - Cybercrime 2026-03-12