daily cyber × ai intelligence

index

tagged

[CVE-2026-65015]

1 edition · 1 item

September 16, 2026

  • Two patched n8n agent flaws turn limited chat privileges into credential access. CVE-2026-65015 lets a read-only Project Viewer ask run_node_tool to execute arbitrary nodes with project credentials, potentially reaching host commands under specific configurations. CVE-2026-59207 makes the agent’s MCP client ignore allowed-domain restrictions and send credentials to an attacker-controlled host. The respective fixes are 2.29.8/2.30.1 and 2.27.4/2.28.1 (deturris.io). · AI & Agent Security

in CVE-2026-76461 Gives Remote Attackers Root on Cisco Email Gateways