CVE-2025-68613
Known exploited · CISA KEV
CVSS 9.9 CRITICAL: n8n is an open source workflow automation platform. EPSS 99% (100th percentile).
CISA federal remediation date Mar 25
Vulnerabilities · 187 days ago
CISA ordered federal agencies to patch an actively exploited n8n remote code execution flaw (CVE-2025-68613). The vulnerability lets authenticated attackers run code as the n8n process and risks exposure of API keys, database credentials, OAuth tokens, and CI/CD secrets held in workflows. Apply n8n
Known exploited · CISA KEV
CVSS 9.9 CRITICAL: n8n is an open source workflow automation platform. EPSS 99% (100th percentile).
CISA federal remediation date Mar 25
2 sources covering this story
CISA Flags Actively Exploited n8n RCE Bug as 24,700 Instances Remain Exposed
CISA adds n8n RCE flaw CVE-2025-68613 to KEV after active exploitation; 24,700 exposed instances raise compromise risk.
CISA orders feds to patch n8n RCE flaw exploited in attacks
Cybersecurity and Infrastructure Security Agency (CISA) ordered government agencies on Wednesday to patch their systems against an actively exploited n8n vulnerability.
Part of the PlainSec briefing for 2026-03-25