CVE-2025-68613
Sfruttamento noto · CISA KEV
CVSS 9.9 CRITICAL: n8n is an open source workflow automation platform. EPSS 99% (100º percentile).
Data di correzione federale CISA 25 mar
Vulnerabilità ed exploit · Attacco ad app web
CISA ha ordinato alle agenzie federali di patchare una RCE in n8n (CVE-2025-68613). La vulnerabilità è stata sfruttata in attacchi attivi. Un attaccante autenticato può eseguire codice con i privilegi del processo n8n e compromettere API keys, database credentials, OAuth tokens e segreti CI/CD.
2 fonti · 12 mar
Sfruttamento noto · CISA KEV
CVSS 9.9 CRITICAL: n8n is an open source workflow automation platform. EPSS 99% (100º percentile).
Data di correzione federale CISA 25 mar
The Hacker News
CISA Flags Actively Exploited n8n RCE Bug as 24,700 Instances Remain Exposed
CISA adds n8n RCE flaw CVE-2025-68613 to KEV after active exploitation; 24,700 exposed instances raise compromise risk.
originaleBleepingComputer
CISA orders feds to patch n8n RCE flaw exploited in attacks
Cybersecurity and Infrastructure Security Agency (CISA) ordered government agencies on Wednesday to patch their systems against an actively exploited n8n vulnerability.
originalePart of the PlainSec briefing for 2026-03-23
Every edition of this story: CISA Ordina Patch per RCE in n8n