Exploitation ongoing with high activity in latest observed window (3 mentions)
Immediate actions
Patch n8n n8n systems immediately
Assume compromise if assets are exposed
Hunt for exploitation attempts and persistence artifacts
Increase monitoring for publicly documented tradecraft
Recommended action window: Immediate (within 24h)
NVD description
n8n is an open source workflow automation platform. Versions starting with 1.65.0 and below 1.121.0 enable an attacker to access files on the underlying server through execution of certain form-based workflows. A vulnerable workflow could grant access to an unauthenticated remote attacker, resulting in exposure of sensitive information stored on the system and may enable further compromise depending on deployment configuration and workflow usage. This issue is fixed in version 1.121.0.
n8n just got a CVSS 10.0 public exploit.
CVE-2026-21858 (“Ni8mare”):
unauthenticated file read → full RCE. Working PoC is circulating.
Any internet-facing n8n that missed the patch is one request away from compromise.
https://github.com/Chocapikk/CVE-2026-21858
#Cybersecurity#AI#AISecurity#MCP#Claude#GPT#Infosec#Trending#RCE#AppSec
Post summary
The tweet announces CVE-2026-21858 (CVSS 10.0) in n8n as an unauthenticated file-read-to-RCE with a circulating public exploit linked via GitHub, warns unpatched instances are at immediate risk, but does not report active in-the-wild exploitation.
The post advertises an attacker infrastructure pipeline targeting multiple CVEs but does not provide PoCs, exploit code, active exploitation evidence, patches, or technical details, placing it in a general informational category.
Found an open directory hosting a layered financial fraud operation across three simultaneous tracks: a Magecart-style card skimmer chain, a mass CVE exploitation framework, and a trojan distributed through Chinese streaming software packaging. All of it feeding the same PII collection pipeline.
The skimmer track starts with FOFA. The actor runs automated queries targeting WooCommerce, Magento, and Stripe-integrated checkout pages, sorting results into structured target lists by category: builder_woo_checkout, stripe_woo_checkout, magento_checkout, checkout_cdn_js. Output lands in pii_consolidated.csv, with a second batch file visible alongside it. This has been running in passes.
The skimmer component is a WooCommerce and Stripe-targeted Magecart payload. Injection engine supports page-level download, mitmproxy transparent proxy, and browser console delivery. C2 receiver runs on the same host. Target profile: Stripe Elements checkout pages, WooCommerce wc-ajax endpoints.
The exploitation track runs in parallel. poc_scanner.py drives 300 concurrent probes against FOFA-sourced targets through a three-stage pipeline: liveness check, service fingerprinting, then PoC verification. CVEs being actively weaponized:
CVE-2026-21858 — n8n unauthenticated RCE, CVSS 10.0
CVE-2026-6815 — Casdoor path traversal to RCE, CVSS 9.8
CVE-2026-32604 — Spinnaker shell injection, CVSS 10.0
CVE-2026-34486 — Tomcat Tribes auth bypass to RCE, CVSS 9.8
CVE-2026-25212 — Percona PMM RCE, CVSS 9.9
CVE-2026-35273 — PeopleSoft unauthenticated SSRF to RCE, CVSS 9.8
CVE-2026-23744 — MCPJam Inspector unauthenticated RCE, CVSS 9.8
CVE-2026-42167 — ProFTPD
CVE-2026-6182 — SQL injection auth bypass
CVE-2025-24587, CVE-2025-4396
A separate WordPress track runs alongside: mass SQL injection via wp_sqli_mass.py, aggressive dump via wp_aggressive_dump.py, PhpMyAdmin brute-force against the same pool.
The trojan track is socially engineered. 直播助手化.v2.exe presents as a legitimate Chinese streaming helper application. VMProtect 3.2–3.5 wrapping. 29/70 on VirusTotal at time of analysis. Family: flystudio, chinad, dlii. It ships with HPSocket4C.dll, pb.dll, pb64.dll, and gzip.dll as side-loaded components. The infection surface is Chinese-speaking streaming users who would recognize the product name as familiar tooling. C2 routes through v2ray.
Two license spoofing servers complete the toolkit. bypass_server.py impersonates http://premium.dotbypasser.workers.dev, handling RSA-OAEP encrypted license exchange and returning forged validation responses with 10-year expiry timestamps. fake_auth_server.py covers a separate streaming platform, impersonating http://api.vmks.cn and related domains, returning fake authorization tokens. Both appear to serve tooling distribution rather than direct victim infrastructure.
One additional finding on the C2 host: evidence of AI-assisted offensive operations. A DeepSeek API configuration points to http://api.deepseek.com through an Anthropic-compatible interface, and a structured offensive security framework containing 70+ purpose-built skill modules for vulnerability classes including SQLi, XSS, SSRF, RCE, IDOR, OAuth, SAML, cloud misconfiguration, Kubernetes, CI/CD, M365/Entra, VMware vCenter, and supply chain recon. The actor is running systematized, AI-assisted attack methodology. This pattern is increasingly documented across financially motivated operations.
OPSEC failure on an otherwise capable operator. filter_cn.py is on the box and actively used. It strips Chinese IP ranges from FOFA output sets before exploitation runs begin. The actor is deliberately skipping domestic targets, a consistent behavioral marker across Chinese financially motivated operations. Additionally, the FOFA API credential is hardcoded in cleartext across the client scripts. Easy attribution anchor.
Post summary
The passage outlines an active threat actor using scripted exploitation tools to weaponize a series of newly disclosed CVEs, while also running Magecart skimming and trojan distribution, and employs AI‑assisted attack frameworks.
The post discloses a CRITICAL unauthenticated RCE vulnerability in n8n (CVE-2026-21858) and links to a GitHub PoC repository, with no mention of active exploitation, patches, or tools beyond the PoC.
We are continuing to expand our n8n RCE vulnerability scanning - most recently adding CVE-2026-27495 (CVSS 9.4) tagging as well. You can track our various n8n scan results here for the most well known critical vulns: https://dashboard.shadowserver.org/statistics/combined/time-series/?date_range=30&source=http_vulnerable&source=http_vulnerable6&tag=cve-2025-68613%2B&tag=cve-2025-68668%2B&tag=cve-2026-21858%2B&tag=cve-2026-21877%2B&tag=cve-2026-25053%2B&tag=cve-2026-25056%2B&tag=cve-2026-27495%2B&dataset=unique_ips&limit=100&group_by=tag&stacking=overlap&auto_update=on
Top affected: US, Germany & France. https://t.co/mEUZ9Is6bf
Post summary
The post announces the addition of CVE-2026-27495 to their n8n RCE scanning list, provides a dashboard link for tracking, and notes the top affected countries, without mentioning exploits, patches, or active attacks.
🚨 CVE-2026-21858 “Ni8mare” (CVSS 10.0): n8n AI workflow automation pre-auth RCE—full control of exposed instances. Treat as internet-facing shell. https://socprime.com/blog/cve-2026-21858-vulnerability/
Post summary
The post announces a high‑severity pre‑authentication RCE in n8n, noting its potential for full system control, but provides no evidence of exploitation, PoC, or patch information.
The tweet serves as a daily threat digest announcing five CVEs as critical exploits disclosed today, without providing technical details, PoCs, exploit code, active exploitation evidence, or remediation information.
n8n “Ni8mare” chain (CVE-2026-21858) is a clean unauthenticated arbitrary file read → RCE path.
Public PoCs are circulating. CVSS 10.0. Workflow automation platforms that expose too much of the host filesystem through their node/execution model keep producing these.
If you run n8n anywhere near an untrusted network, this one is high priority.
https://github.com/Chocapikk/CVE-2026-21858
#Cybersecurity#AI#AISecurity#MCP#Claude#GPT#Infosec#Trending#RCE#AppSec
Post summary
The message announces CVE‑2026‑21858, highlights its high‑severity RCE via unauthenticated file read, and shares a publicly available PoC in a GitHub repository.
CVE-2026-21858 (“Ni8mare”) has a 10.0 CVSS and active underground interest. But does that mean high exploitation risk? Intel 471’s Mehmet Berkay Yüksel explains how to separate noise from real risk. Register here: https://hubs.la/Q045VDLs0
#threatintel#cybersecurity#cyberrisk https://t.co/cRSHVU7Ehq
Post summary
The tweet highlights CVE‑2026‑21858 with a 10.0 CVSS and underground interest, but provides no PoC, exploit code, or patch information, merely inviting readers to a webinar to assess the real risk.
CVE-2026-21858 (“Ni8mare”) has a 10.0 CVSS and active underground interest. But is it truly high risk? Join us March 11 at 11:00 AM ET / 16:00 CET as we break down the real-world exploitation assessment: https://hubs.la/Q043CSv30
#threatintel#cybersecurity#cybercrime#Ni8mare https://t.co/DX5EkhZKei
Post summary
The tweet promotes a scheduled session to analyze the real‑world exploitation risk of CVE‑2026‑21858 (Ni8mare) with a 10.0 CVSS, but it provides no evidence of active exploitation, PoC, or patch.
💀 CRITICAL Exploits Trending
├ CVE-2026-21858 · CVE-2026-53576 (Kestra) · PoC live
├ CVE-2026-61732 · PoC live
└ CVE-2020-24186 · CVE-2025-24813 (Apache GOExploiter) · PoC live
Post summary
The post highlights the availability of Proof-of-Concept code for multiple CVEs, labeling them as critical and trending, without mentioning active exploitation, patches, or detailed technical analysis.
#HermesAgent こんな使い方もされているのか。しかし、バレ方が間抜け感。
中国語圏の攻撃者、DeepSeekとHermes Agentで自律型 サイバー攻撃を実行 Unit 42が7件の脆弱性 悪用を確認(CVE-2026-33017,CVE-2026-21858/CVE-2025-68613)
https://rocket-boys.co.jp/security-measures-lab/chinese-actor-deepseek-hermes-agent-autonomous-attack/
Post summary
Unit 42 confirms that the Chinese actor DeepSeek and Hermes Agent executed autonomous attacks exploiting seven CVEs, including CVE‑2026‑33017, CVE‑2026‑21858, and CVE‑2025‑68613.
🔒 CYBERSECURITY, PRIVACY & OPEN SOURCE ROUNDUP — September 19, 2026
1️⃣ DOCKER HYPERVISOR ESCAPE: THREE LINES OF BASH UNLOCK THE HOST FILESYSTEM
A container that is supposed to be locked away just got full read and write access to the machine running it. In CVE-2026-77179, Docker's virtual machine monitor relies on virtio-fs, and the file server runs on the host side. Because of a time-of-check-to-time-of-use flaw, a container can open a file, delete it while still holding the handle, and replace the parent folder with a symlink — the kernel then follows that link to anywhere on the host. The whole chain takes three lines of bash, and the researcher published a full technical breakdown of the escape.
🔹 @orenyomtov
2️⃣ GOOGLE PIXEL MODEM ZERO-DAY IS BEING EXPLOITED IN THE WILD
Google confirmed that a zero-click vulnerability in the Pixel cellular modem is already being used in limited, targeted attacks. A logic error lets an attacker bypass permission checks and gain elevated access on the device, with one constraint: the attacker needs to be physically nearby. The September security update (patch level 2026-09-05 or later) fixes CVE-2026-58704, and CISA has added it to its Known Exploited Vulnerabilities catalog.
🔹 @IntCyberDigest
3️⃣ N8N GETS A CVSS 10.0 PUBLIC EXPLOIT
The popular open-source workflow automation tool n8n just received a fully weaponized vulnerability: CVE-2026-21858, nicknamed "Ni8mare," scores a perfect 10.0. It starts with an unauthenticated file read and escalates to full remote code execution, and a working proof of concept is already circulating. Any internet-facing n8n instance that missed the patch is one request away from being fully compromised.
🔹 @PadhiyarRushi
4️⃣ BREVO SUPPLY-CHAIN ATTACK REACHES OVER 100,000 WEBSITES
A supply-chain attack against the Brevo email platform may have affected more than 100,000 websites through infrastructure they already trusted. Attackers used a compromised Cloudflare API key to deploy a malicious worker that modified Brevo-hosted scripts at the edge: visitors were shown fake "prove you're human" click-fix prompts, while logged-in WordPress admins could have a malicious plugin installed through their active session. Brevo's origin files stayed clean, which makes the attack even harder to spot.
🔹 @Huntio
5️⃣ SOLARWINDS ARM: A HARD-CODED KEY OPENS THE DOOR TO REMOTE CODE EXECUTION
SolarWinds disclosed a hard-coded static key in its Application Resource Management product that can be abused for unauthenticated remote code execution. CVE-2026-28326 affects ARM 2026.2 and earlier, and is fixed in 2026.2.1. The company did not report any in-the-wild exploitation, but a static key of this kind is exactly the sort of thing scanners look for.
🔹 @TheHackersNews
6️⃣ PUBLIC CVE DISCLOSURES ARE ACCELERATING AT A TERRIFYING PACE
A data point worth pausing on: tallying publicly disclosed CVEs month by month, the recent trend looks alarming — and the global surge in vulnerability hunting activity suggests this is only the beginning. The researcher behind the analysis expects the numbers to jump by an order of magnitude in the coming months, which means patching cadence and exposure reduction are no longer optional hygiene.
🔹 @nekono_naha
7️⃣ UBUNTU 26.10 MOVES TO THE LINUX 7.3 KERNEL
Ubuntu 26.10, the latest interim release of the always-changing flavor, is shipping with the Linux 7.3 kernel. For people who track where the desktop distribution stands, it marks another step in Ubuntu's steady climb toward the newest mainline kernel features.
🔹 @phoronix
8️⃣ IPHONE LOCKDOWN MODE JUST BEAT AN FBI EXTRACTION ATTEMPT
Apple's Lockdown Mode is having a moment: the FBI said it was unable to extract data from a journalist's iPhone because the device had Lockdown Mode enabled. The setting is not a magic shield, but it drastically shrinks the attack surface by restricting features that sophisticated attacks rely on, from certain attachments and FaceTime requests to configuration profiles and untrusted wireless connections.
🔹 @cyber_razz
💭 The common thread this week is that every boundary we assumed was solid turned out to have a door: a container "wall" that a symlink walks through, a modem that gets hit with zero clicks before the phone is even unlocked, an email platform trusted by 100,000 sites that was bent through a single API key. The lesson is not to panic — it is to treat isolation, patching cadence, and least privilege as the actual product, because in 2026 the trust you assume is the thing that gets exploited.
Which of these hits closest to home — containerized servers, the phone in your pocket, or a website you help run? Tell me below 👇
#CyberSecurity#OpenSource#Privacy
Post summary
The text covers multiple CVEs including one confirmed as actively exploited (CVE-2026-58704) with patches available, alongside other disclosures detailing technical vulnerabilities and PoC availability.
New research shows a gap in CISA KEV for n8n. CVE-2025-68613 can be chained with CVE-2026-21858 (not in KEV) for unauthenticated RCE, and exploitation is already happening. 14K+ exposed instances and links to MuddyWater suggest the risk is understated: https://www.vulncheck.com/blog/n8n-needs-more-kev?utm_source=x&utm_medium=organic-social
Post summary
The post highlights that CVE-2025-68613 and CVE-2026-21858 can be chained for unauthenticated RCE and that this exploit is already in use, with over 14,000 exposed instances.
CVE-2026-21858 (“Ni8mare”) has a 10.0 CVSS and active underground interest. But is it truly high risk?
On March 11, learn how Intel 471 evaluates real-world exploitation likelihood. Sign up today: https://hubs.la/Q045dnl_0
#threatintel#vulnerability https://t.co/wpslM1abB0
Post summary
The tweet highlights a high‑scoring CVE with underground interest but lacks concrete evidence of exploitation, PoC, or patch information. The focus remains on raising awareness rather than providing actionable details.
Read-Only Friday is cancelled.
CVE-2026-21858 just dropped for n8n.
CVSS 10.0. Absolute RCE.
If you think you're safe because it’s "behind a login," you haven't seen the attack path I just mapped.
Time to wake up. 🧵👇 https://t.co/PLJUMdGxWk
Post summary
The tweet announces CVE‑2026‑21858 for n8n, noting an absolute RCE with CVSS 10.0 and a new attack path, but does not mention PoC, active exploitation, or patches.
The post announces the availability of a functional exploit for CVE-2026-21858, explicitly tagged as [EXPLOIT] and [CRITICAL/PoC], with a link to an exploit repository.