September 16, 2026
- Two patched n8n agent flaws turn limited chat privileges into credential access. CVE-2026-65015 lets a read-only Project Viewer ask
run_node_tool to execute arbitrary nodes with project credentials, potentially reaching host commands under specific configurations. CVE-2026-59207 makes the agent’s MCP client ignore allowed-domain restrictions and send credentials to an attacker-controlled host. The respective fixes are 2.29.8/2.30.1 and 2.27.4/2.28.1 (deturris.io).
· AI & Agent Security
in CVE-2026-76461 Gives Remote Attackers Root on Cisco Email Gateways
August 17, 2026
- n8n schema-name-to-RCE (CVE-2026-33696). A prototype-pollution path in the gsuiteadmin node escalates from a controllable schema name to remote code execution (writeup).
· Vulnerabilities & Exploits
in One Video Call to Kernel: Unisoc Baseband Chain Gives Full Android Takeover
August 6, 2026
- 321 live n8n instances found accepting API tokens leaked in public GitHub commits. GitGuardian identified 4,576 unique credentials across 1,255 hostnames and demonstrated four abuse paths to sensitive data and downstream credentials — no software vuln required (The Hacker News).
· Vulnerabilities & Exploits
in OpenAI's Rogue-Agent Post-Mortem: A Swarm That Rebuilt Its Own Message Board
July 28, 2026
- n8n patched a high-severity expression-sandbox escape (affecting <2.31.5 and 2.32.0–2.32.1) that let an authenticated workflow editor run OS commands as the n8n process; Security Joes found it while probing the February fix for CVE-2026-27577 (The Hacker News).
· Vulnerabilities & Exploits
in Agentic AI Muscles Into the Offensive Toolkit
July 17, 2026
SonicWall SMA1000 SSL-VPN appliances are under broad-scale exploitation via CVE-2026-15409 leveraging public PoC code, with CVE-2026-56155 remaining unfixed despite July patches. Nighthawk 1.0 C2 released with cross-platform UI and improved evasion capabilities including CET-compatible call-stack masking. AI agents can be compromised through data injection attacks that corrupt trusted facts, enabling attackers to trick agents into executing commands or clicking malicious links without direct prompt injection. Scattered Spider members received 5.5-year sentences for the 2024 Transport for London ransomware attack affecting 7 million users.