n8n security advisory (AV26-880)
At a glance
- Severity
- Medium
- Used in attacks
- No flaws named
- Vendors and products
- GitHub
- Reported by
- 1 outlet
Serial Number: AV26-880 Date: September 3, 2026 As of September 3, 2026, n8n is affected by vulnerabilities in the following product: n8n Prior to 1.123.76 Prior to 2.35.4 Prior to 2.36.2 Prior to 2.37.7 Prior to 2.38.2 The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available. Overview · n8n-io/n8n · GitHub…
We summarise and link; this source is not one we hold a licence to reproduce. Everything below is what CyberBrief adds: the vulnerabilities involved, whether they are being exploited, who is named, and who else covered it.
Coverage
One outlet has carried this so far.
2026-09-03 18:59 UTC
Related stories
- Malware bypasses browser checks to force install Chrome, Edge extensions
BleepingComputer · 2026-09-16
- Google Pixel phones pwned in zero-click attacks
The Register · 2026-09-16
- Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution
The Hacker News · 2026-09-16
- PHP Webshell Campaign Targets WordPress Through Critical WooCommerce Plugin Bug
Infosecurity Magazine · 2026-09-16
- Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories
The Hacker News · 2026-09-16