Exploitation timeline
Threadlinqs has recorded 10 N8n CVEs published between and . The busiest month was 2026-02 (5 new CVEs). 1 of them (10%) are listed in CISA KEV, which means exploitation in the wild has been confirmed.
Most exploited vulnerabilities
Ranked with CISA KEV listings first, then EPSS exploit probability, then CVSS score. Showing 10 of 10 tracked N8n CVEs.
- CVE-2025-68613critical 9.9KEVEPSS 79.2%
- CVE-2026-21877critical 9.9EPSS 14.1%
- CVE-2026-21858critical 10EPSS 6.6%
- CVE-2026-56777medium 5EPSS 0.3%
- CVE-2026-25056high 8.8EPSS 0.2%
- CVE-2026-25115critical 9.9EPSS 0.1%
- CVE-2025-68668critical 9.9EPSS 0.1%
- CVE-2026-25049critical 9.9EPSS 0%
- CVE-2026-25053critical 9.9EPSS 0%
- CVE-2026-25052critical 9.9EPSS 0%
Products affected
Threadlinqs normalises CPE and CNA product records across all 10 CVEs; 1 distinct N8n product is affected. The most frequently affected:
- N8n 10 CVEs
Threat activity
4 tracked threat campaigns reference N8n products or exploit N8n CVEs:
- Critical Type Confusion in isolated-vm ExternalCopy Enables Guest-to-Host Sandbox Escape and RCE (GHSA-864f-rcv7-6rh4)CRITICAL
- CVE-2026-59208: Cross-Issuer Impersonation in n8n Enterprise Token ExchangeHIGH
- n8n Workflow Automation RCE via Expression Injection — CVE-2025-68613 (CVSS 9.9) Active Exploitation by Zerobot BotnetCRITICAL
- n8n Multi-CVE Vulnerability Cascade — Expression Sandbox Escape, Pyodide RCE, Arbitrary File Write, Command Injection (9 CVEs, 2× CVSS 10.0)CRITICAL
How to prioritise N8n patching
This order follows the data Threadlinqs holds for N8n, not a generic severity checklist:
- 1 of 10 N8n CVEs (10%) are in CISA KEV: treat them as actively exploited and remediate them first, starting with CVE-2025-68613.
- Outside KEV, the highest EPSS scores are CVE-2026-21877 (14.1%), CVE-2026-21858 (6.6%), CVE-2026-56777 (0.3%).
- 8 CVEs score Critical and 1 High on CVSS v3 (maximum 10, average 9.3); sequence these after KEV and high-EPSS items.
About this data
Vendor attribution comes from the CNA and CPE product records of each CVE, folded to one vendor name; CVSS, EPSS and KEV status are read from the Threadlinqs CVE catalog; campaign and actor links come from tracked threat records. Counts reflect the data as of 2026-10-05 and refresh daily.