Newsn8n CVE Firehose — 8 Critical Vulnerabilities in FebruaryThe Hacker News·high signalXBlueskyLinkedInCopy linkEight CVEs in February with CVSS up to 10.0. CVE-2026-21858 (Ni8mare) allows unauthenticated RCE. All self-hosted n8n before v1.121.0 vulnerable.SourceSource pageThe Hacker News↳ Follow the threadThreat pattern / ContrastDeepSeek Harness CVE-2026-82533 (CVSS 9.4): a sandboxed agent could flip its own session to 'danger-full-access' through the unauthenticated local UIThe Hacker NewsPolicy dependency / Stack layerCROSS-CATEGORY: Three Independent Agent-Action Gates Shipped in 48 Hours, All Judging the Command Against Stated IntentProduct Hunt, github.com/AGGIB/Stroq and rewarelabs.com (three independent sources; the 72% figure is Reware's own)Stack layer / Threat patternRAGFlow 0.27.2 rewrites its Agentic RAG retrieval framework and patches a starlette CVEGitHubStack layer / Threat patternColibrì runs 744B to 2.8T MoE models on consumer hardware in pure C by streaming experts off diskGitHub TrendingStack layer / Threat patternGoogle's Agent Development Kit for Python Carries a CVSS 10.0 Unauthenticated RCE via Test Session ReplayOffSeq Threat RadarStack layer / Threat patternAWS Security Agent MCP server could hand a scanned workspace's source archive, credentials included, to an attacker-owned S3 bucketNVDStack layer / Threat patternIBM discloses four critical MCP flaws in Langflow and ContextForge, three of them command execution through MCP stdio configurationNVD / IBM Security BulletinThreat pattern / ContrastIn a random draw of 400 MCP servers, only 48.8% complete a handshake, and 58.8% of tools omit safety annotationsarXiv 2609.10962