CVE-2025-0539: Octopus Server
High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.
In affected Microsoft Windows versions of Octopus Deploy, the server can be coerced into sending server-side requests that contain authentication material allowing a suitably positioned attacker to compromise the account running Octopus Server and potentially the host infrastructure itself.
Affected products
- Octopus Octopus Server: from 2.6.0, before 2024.3.13071 (fixed in 2024.3.13071); from 2024.4.401, before 2024.4.7065 (fixed in 2024.4.7065)
Published 2025-04-10. Last modified 2026-06-17.