CVE-2025-68613
Known exploited · CISA KEV
CVSS 9.9 CRITICAL: n8n is an open source workflow automation platform. EPSS 99% (100th percentile).
CISA federal remediation date Mar 25
Vulnerabilities & Exploits · Web App Attack
CISA ordered federal agencies to patch an actively exploited remote code execution flaw in n8n (CVE-2025-68613). The flaw lets authenticated attackers run code as the n8n process and access stored API keys, tokens, and credentials.
2 sources · Mar 12
Known exploited · CISA KEV
CVSS 9.9 CRITICAL: n8n is an open source workflow automation platform. EPSS 99% (100th percentile).
CISA federal remediation date Mar 25
The Hacker News
CISA Flags Actively Exploited n8n RCE Bug as 24,700 Instances Remain Exposed
CISA adds n8n RCE flaw CVE-2025-68613 to KEV after active exploitation; 24,700 exposed instances raise compromise risk.
originalBleepingComputer
CISA orders feds to patch n8n RCE flaw exploited in attacks
Cybersecurity and Infrastructure Security Agency (CISA) ordered government agencies on Wednesday to patch their systems against an actively exploited n8n vulnerability.
originalPart of the PlainSec briefing for 2026-03-13
Every edition of this story: CISA Orders Federal Agencies to Patch n8n RCE