n8n-io vendor intelligence

n8n-io Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting n8n-io products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.

Browse n8n-io KEVs Full KEV feed
Total KEVs
2
Known exploited vulnerabilities affecting n8n-io products
In CISA KEV
1
Records also listed in the official catalog
Beyond CISA KEV
1
Additional exploited CVEs absent from CISA KEV
Sensor Observed
1
n8n-io KEV with sensor-observed exploitation activity

The catalog gap matters for n8n-io exposure

One of the two exploited n8n-io CVEs tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss half of this vendor portfolio.

50%
Covered by CISA
50%
Beyond CISA
1
Product families

Attested n8n-io CVEs

Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.

How exploitation is verified
CVE / description Product Confidence CISA KEV Added
CVE-2026-21858

n8n Vulnerable to Unauthenticated File Access via Improper Webhook Request Handling

n8n Confirmed Beyond CISA 07 Feb 2026
CVE-2025-68613

n8n Vulnerable to Remote Code Execution via Expression Injection

n8n Confirmed In CISA 01 Jun 2026

Showing 2 of 2 n8n-io known exploited vulnerabilities.

Recurring weakness patterns

Input validation and control account for two mapped occurrences across this n8n-io KEV portfolio.

Browse all KEVs →

Early warning alerts

Get alerts on high-impact exploitation

Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.

Occasional high-impact alerts. Unsubscribe anytime. See our Privacy Policy.