Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

100,000+ n8n Instances Exposed to Internet Vulnerable to RCE Attacks

A significant security vulnerability has been identified in the n8n workflow automation platform, placing over 100,000 internet-exposed instances at risk.

A significant security vulnerability has been identified in the n8n workflow automation platform, placing over 100,000 internet-exposed instances at risk.

Researchers from The Shadowserver Foundation found that 105,753 unique n8n instances are susceptible to remote code execution (RCE) attacks due to CVE-2026-21858 .

n8n facilitates automation by connecting different applications, services, and databases, streamlining business processes and data management. The platform's widespread adoption underscores the critical nature of this vulnerability.

CVE ID CVSS Score Affected Product Vulnerability Type Impact

CVE-2026-21858 10.0 n8n Workflow Automation Remote Code Execution (RCE) Full instance takeover, data exposure

A significant security vulnerability has been identified in the n8n workflow automation platform, placing over 100,000 internet-exposed instances at risk.
Madison Drake · Thehackingpost

CVE-2026-21858, with a CVSS score of 10.0, is classified as a critical threat. The issue arises from content-type confusion in n8n's webhook handling . Attackers can exploit this flaw by sending specially crafted HTTP requests with manipulated headers.

The vulnerability permits unauthenticated attackers to execute arbitrary code, access sensitive files, extract credentials, and forge administrator sessions, leading to full instance control. A scan by The Shadowserver Foundation on January 9, 2026, revealed alarming numbers.

Of 230,562 IP addresses running n8n, approximately 105,753 instances were vulnerable, equating to nearly 46 percent of exposed deployments.

The vulnerability affects n8n versions 1.65.0 through 1.120.x. Immediate upgrades to version 1.121.0 or later are essential, as these include the necessary security patch .

Advertisement

Given the public availability of proof-of-concept exploits and active scanning for vulnerable instances, organizations should update n8n installations promptly, restrict network access with firewalls, and monitor logs for suspicious requests. Reviewing connected integrations and credentials is also advised.

For enhanced security, consider using a VPN or private network rather than exposing systems to the internet. The n8n community, along with security researchers, continues to monitor the threat landscape for further vulnerabilities.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories