Back to Feed
VulnerabilitiesMar 12, 2026

CISA Flags Actively Exploited n8n RCE Bug as 24,700 Instances Remain Exposed

CISA added CVE-2025-68613, a critical remote code execution vulnerability in n8n (CVSS 9.9), to its Known Exploited Vulnerabilities catalog due to active exploitation in the wild. The flaw stems from an expression injection vulnerability, with approximately 24,700 instances remaining exposed and unpatched.

Summary

CISA added CVE-2025-68613, a critical remote code execution vulnerability in n8n (CVSS 9.9), to its Known Exploited Vulnerabilities catalog due to active exploitation in the wild. The flaw stems from an expression injection vulnerability, with approximately 24,700 instances remaining exposed and unpatched.

Indicators of Compromise

  • cve — CVE-2025-68613