NullSecurityX[verified]@NullSecurityXExploit
The post discloses a zero‑click unauthenticated RCE in n8n with a concrete SSTI exploit snippet and a link to a PoC; it does not indicate active exploitation or patch status.
GovCERT.CZ[verified]@GOVCERT_CZPatch
The post warns of two critical CVEs in n8n, details their technical exploitation vectors, and urges users to upgrade to specified patched versions.
Modat[verified]@modat_magnifyActive Exploitation
The post confirms active exploitation of CVE‑2025‑68613 in n8n, details the RCE flaw, and provides the specific patched versions for remediation.
Pillar Security[verified]@Pillar_secPatch
Pillar Security disclosed a critical zero‑click RCE in n8n, identified more than 50,000 vulnerable forms, and urged self‑hosted users to update to the latest version to mitigate the issue.
Security Arsenal, LLC[verified]@SecurityAr58409Patch
The tweet promotes a blog article that offers a patching guide for the n8n RCE vulnerabilities CVE-2026-27577 and CVE-2026-27493.
DarkShadow@darkshadow2bdPoC
The message discloses a zero‑click unauthenticated RCE in n8n (CVE‑2026‑27493) and supplies a concrete SSTI-to-RCE payload, but does not report active exploitation or provide a patch.
Brut 🇮🇳@wtf_yodhhaDisclosure
The post announces a newly discovered zero‑click unauthenticated remote code execution vulnerability (CVE‑2026‑27493) affecting n8n, without providing PoC, exploit code, active exploitation evidence, or mitigation details.
Kevin Poireault@kpoireaultDisclosure
Researchers at Pillar Security announced two new critical vulnerabilities in self‑hosted and cloud n8n deployments, including CVE‑2026‑27493, but did not provide further technical or exploit details.