CRITICAL: Patch n8n Now — Unauthenticated RCE Affects 100K Servers

Share
CRITICAL: Patch n8n Now — Unauthenticated RCE Affects 100K Servers

Patch immediately. CVSS 10.0.

A maximum-severity flaw in n8n allows unauthenticated attackers to fully compromise servers and access all connected systems including API keys, databases, and cloud services.

Vulnerability Summary

CVECVE-2026-21858
Severity10.0 CRITICAL
Affectedn8n versions < 1.121.0
ExploitedPoC available
PatchUpgrade to 1.121.0+

What's at Risk

Attackers can chain this vulnerability to:

  • Read arbitrary server files without credentials
  • Extract database and config files
  • Forge admin session cookies
  • Execute commands on the underlying system

With n8n's access to connected services (Google Drive, Salesforce, CI/CD pipelines, payment processors), a single compromise can cascade across your entire infrastructure.

Immediate Actions

  1. Upgrade to n8n version 1.121.0 or later
  2. Disable publicly accessible webhook/form endpoints until patched
  3. Audit existing workflows for exposed Form nodes
  4. Review logs for suspicious webhook activity

Who's Affected

Approximately 100,000 self-hosted n8n instances globally. Cloud-managed deployments are less impacted.


Tags: Critical, CVE-2026-21858, n8n, RCE, Patch Now

Read more

Nx Console VS Code Extension Compromised — 2.2 Million Installs Exposed to Credential Stealer With Sigstore Supply Chain Poisoning Capability

Nx Console VS Code Extension Compromised — 2.2 Million Installs Exposed to Credential Stealer With Sigstore Supply Chain Poisoning Capability

A compromised version of the Nx Console extension — a popular VS Code plugin with over 2.2 million installations — was published to the Visual Studio Code Marketplace after an attacker leveraged stolen developer credentials to inject a multi-stage credential stealer into the official nrwl/nx GitHub repository. The malicious version

By Zero Day Wire
Pre-Stuxnet Sabotage Malware Fast16 Confirmed as Nuclear Weapons Simulation Tampering Tool Dating Back to 2005

Pre-Stuxnet Sabotage Malware Fast16 Confirmed as Nuclear Weapons Simulation Tampering Tool Dating Back to 2005

Symantec and Carbon Black have published a definitive analysis confirming that Fast16, a Lua-based malware framework first surfaced by SentinelOne weeks ago, was purpose-built to sabotage nuclear weapons testing simulations. The findings establish Fast16 as the earliest known cyber sabotage tool targeting nuclear weapons research — predating the first known version

By Zero Day Wire