Skip to content
Vulnerability intelligence

CVE-2026-56275

n8n disclosed 11 CVEs including a CVSS 10.0 in its MCP endpoint. Flowise disclosed 6 including two RCE paths through its Custom MCP feature. The tools enterprises deploy to ‘become AI-native’ are the least secure software in the stack.

2026