Newsn8n CVE Firehose — 8 Critical Vulnerabilities in FebruaryThe Hacker News·high signalXBlueskyLinkedInCopy linkEight CVEs in February with CVSS up to 10.0. CVE-2026-21858 (Ni8mare) allows unauthenticated RCE. All self-hosted n8n before v1.121.0 vulnerable.SourceSource pageThe Hacker News↳ Follow the threadPolicy dependency / Stack layerSGLang Hit With Unauthenticated Pickle RCE via /update_weights_from_tensor, the Fourth Critical Inference-Stack CVE in Four WeeksCERT Coordination CenterPolicy dependency / Stack layerAgent Framework stops forwarding headers across redirects and revalidates file skill paths before useGitHubStack layer / Threat patternSureForge encodes a research-plan-verify-review gate sequence as a plain-text agent skillGitHubStack layer / Threat patternSnyk put its agent-skill scanner behind a free web page called Skill InspectorSnyk LabsPolicy dependency / Stack layerA replay of 68,266 real Claude Code requests says plain LRU beats the clever KV-cache policiesGitHubStack layer / Threat patternPattern: MCP gateways keep shipping with authentication off by defaultNVDPolicy dependency / Stack layerRIPPLE: an edit confined to one prompt-policy segment changes downstream behavior, so replay candidate edits after previously accepted ones before persistingarXiv 2609.12127Stack layer / Threat patternA critical unauthenticated RCE in the Bifrost MCP gateway: registering a stdio client runs a program on the boxNVD