Vulnerabilità ed exploit · Attacco ad app web

CISA Ordina Patch per RCE in n8n

CISA ha ordinato alle agenzie federali di patchare una RCE in n8n (CVE-2025-68613). La vulnerabilità è stata sfruttata in attacchi attivi. Un attaccante autenticato può eseguire codice con i privilegi del processo n8n e compromettere API keys, database credentials, OAuth tokens e segreti CI/CD.

2 fonti · 12 mar

CVE-2025-68613

NVD KEV

Sfruttamento noto · CISA KEV

CVSS 9.9 CRITICAL: n8n is an open source workflow automation platform. EPSS 99% (100º percentile).

Data di correzione federale CISA 25 mar

Cronologia

Fonti

Part of the PlainSec briefing for 2026-03-23

Every edition of this story: CISA Ordina Patch per RCE in n8n

Altro da oggi