CVE
CVE-2026-59208
n8n: Cross-Issuer Token Exchange Account Binding via Subject-Only Identity Resolution
Exploitation IoCs 7
Filename .ssh/authorized_keys
Filename /dev/shm/.a
Filename /etc/cron.d/.s
Filename /etc/cron.d/.sys_monitor
Filename /tmp/.a
Filename /var/tmp/.a
GitHub Repo Cursor agent
MITRE ATT&CK TTPs 1
Source Articles
⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More
This week's threat landscape highlights critical vulnerabilities in widely used platforms such as WordPress, SonicWall, and Microsoft SharePoint, with active exploitation observed in the wild. A pre-authenticated remote code execution flaw in WordPress Core (CVE-2026-63030 and CVE-2026-60137) enables unauthenticated attackers to execute code, posing a significant risk due to WordPress's global reach. SonicWall SMA appliances were exploited via zero-day vulnerabilities prior to patching, while CISA added a SharePoint RCE (CVE-2026-58644) to its known exploited list. Additionally, new malware frameworks like OkoBot and NadMesh target crypto assets and cloud AI services, indicating evolving attacker tactics leveraging automation and AI.
hacker-news Jul 20, 2026
n8n Token Exchange Flaw Could Let Attackers Log In as Users From Another Issuer
A vulnerability in n8n's Enterprise token exchange feature, tracked as CVE-2026-59208, allowed attackers to log in as users from another issuer due to improper validation of JWT tokens. The flaw occurred when n8n matched incoming tokens solely on the 'sub' claim without verifying the 'iss' (issuer), enabling account takeover if two trusted issuers used overlapping subject identifiers. The issue affects n8n versions prior to 2.27.4 and 2.28.1, and while the feature is limited to Enterprise deployments in preview, it poses a high-severity risk for misconfigured systems.
hacker-news Jul 16, 2026