CISA Flags Actively Exploited n8n RCE Bug as 24,700 Instances Remain Exposed
2026-03-12T07:24:11Z•8f4b0548ebb6545b1aa688b017c78db594ab01b96bb6471f4e693ead4380025a
AI browser phishingCISAFortiGateKEVKadNapLooker StudioPerplexityRust cratesbotnetcross-tenantexpression injectionn8nnpm malwareremote code executionsupply chain
What happened
The collection highlights multiple high‑risk incidents and disclosures: CISA added a critical n8n expression‑injection RCE (CVE-2025-68613, CVSS 9.9) to its KEV list while ~24,700 instances remain exposed; researchers also disclosed two other now‑patched n8n critical flaws (CVE-2026-27577, CVE-2026-27493). Additional notable items include proof‑of‑concept phishing of agentic AI browsers (Perplexity Comet), widespread supply‑chain/cloud compromises (UNC6426 exploiting nx npm), malicious packages and crates exfiltrating developer secrets (malicious npm OpenClaw package; five Rust crates), active
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 8f4b0548ebb6545b1aa688b017c78db594ab01b96bb6471f4e693ead4380025a
- Enrichment time
- 2026-03-12T07:24:11Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.