Nearly 60,000 internet-facing n8n workflow automation servers remain vulnerable to a critical security flaw dubbed “Ni8mare” (CVE-2026-
Discovered by Cyera in November 2025 and patched in n8n version 1.121.0 released in January 2026, the vulnerability stems from improper input validation caused by content-type confusion in Form Submission triggers. Exploitation is alarmingly simple: attackers can upload specially crafted malicious files through public webhooks or forms, forge sessions, inject arbitrary payloads, and ultimately take control of workflows—without any authentication.
Internet scans conducted by Shadowserver identified over 105,000 exposed n8n instances, with nearly 59,000 still unpatched as of January 11. The highest concentrations are in the United States (28,000), Europe (21,000), and Asia (7,500). Given n8n’s popularity—offering 400+ integrations and AI-native automation—compromised servers often store high-value secrets, including API keys, OAuth tokens, database credentials, and CI/CD pipelines.
A breached n8n instance can quickly become an enterprise goldmine, enabling attackers to pivot into cloud platforms, CRM systems like Salesforce, payment gateways, and internal infrastructure. The risk is amplified by n8n’s fair-code license, which encourages self-hosting and has led to widespread public exposure.
Security teams should urgently upgrade to v1.121.0 or later, disable public webhooks where possible, scan for exposed instances, and assume active exploitation risk despite no confirmed attacks yet.
See What’s Next in Tech With the Fast Forward Newsletter
Tweets From @varindiamag
Nothing to see here - yet
When they Tweet, their Tweets will show up here.




