chiprook
← Security
SecurityOctober 6, 2026, 15:29

n8n Patches Two Critical Flaws in One Day

On October 5, 2026, n8n disclosed two vulnerabilities: an expression sandbox escape CVE-2026-86076 (CVSS 8.7) and an argument injection CVE-2026-44790 (CVSS 9.4). Both grant an attacker full control of the server; fixes ship in versions 1.123.76, 2.37.7 and 2.38.2.

n8n Patches Two Critical Flaws in One Day
#N8n
Read next
Security

SolarWinds Patches Two Critical RCE Flaws in Observability Self-Hosted

Security

Dell patches 18 critical flaws in storage and Kubernetes tools

Security

Asus patches critical flaws in routers and motherboards

Security

Fortra Patches Eight BoKS Flaws, Three Rated Critical