Octopus Deploy disclosed CVE-2026-101169, a high-severity insecure JSON deserialization vulnerability that enables authenticated users with permission to edit an Environment or Project to execute arbitrary code in the Octopus Server process. The issue affects Octopus Server deployments on Linux and Windows, including versions from 2019.4.x through 2025.x and vulnerable builds in the 2026.1 through 2026.4 feature branches.
The vendor released patches on September 14 and published Security Advisory 2026-10 on September 29. No workaround or mitigation is available other than upgrading affected self-hosted instances; Octopus Deploy recommends immediate patching. The company reported no known public exploitation at disclosure, while stating that Octopus Cloud environments had already been remediated and require no customer action.

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
Octopus Deploy publicly disclosed CVE-2026-101169 through Security Advisory 2026-10, advising affected Linux and Windows Octopus Server users to upgrade because no alternative mitigation was available. It reported no known public exploitation or malicious use at disclosure.
Octopus Deploy released fixed Octopus Server versions for CVE-2026-101169. The flaw could allow authenticated users permitted to edit Environment or Project objects to execute code in the Octopus Server process.
Nathan Willoughby of Octopus Deploy identified CVE-2026-101169, an insecure JSON deserialization flaw in Octopus Server, during internal testing.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
cryptika.com
Open sourcecybersecuritynews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.