Tracked as CVE-2026-21858 (CVSS score 10), the bug enables remote code execution without authentication.

The post Critical Vulnerability Exposes n8n Instances to Takeover Attacks appeared first on SecurityWeek.