CVE-2026-0704Disclosure(linux / linux_kernel)

MEDIUMCVSS 9.1 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch linux linux_kernel systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

In affected version of Octopus Deploy it was possible to remove files and/or contents of files on the host using an API endpoint. The field lacked validation which could potentially result in ways to circumvent expected workflows.

4.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel
  • octopus_server
  • windows

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 1 mentions (2026-02-25); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Products
linux_kerneloctopus_serverwindows

1 version affected across 3 products

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-02-25: 1Mentions · 2026-02-26: 1Mentions · 2026-02-27: 1Mentions · 2026-03-02: 1Active Exploitation · 2026-02-26: 1Patch / Workaround · 2026-02-26: 1Technical Details · 2026-02-25: 1Technical Details · 2026-02-26: 1Technical Details · 2026-02-27: 1Technical Details · 2026-03-02: 102-2502-2602-2703-02
Signal classification3 categories
Disclosure
250.0%
Active Exploitation
125.0%
General
125.0%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-02-251
Disclosure1
2026-02-261
Active Exploitation1
2026-02-271
Disclosure1
2026-03-021
General1
Full discourse4 posts
  • CRAC Learning - Tech@cracbot
    General

    CVE-2026-0704 (CVSS:5.9, CRITICAL) is Modified. In affected version of Octopus Deploy it was possible to remove files and/or contents of files on the host using an API ..https://nvd.nist.gov/vuln/detail/CVE-2026-0704 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post references CVE-2026-0704, noting a critical vulnerability in Octopus Deploy that permits file removal via an API, but it provides no evidence of exploitation, PoC, or patch.

    0000036
    173 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-0704 - Critical In affected version of Octopus Deploy it was possible to remove files and/or contents of files on the host using an API endpoint. The field lacked validation which could potentially result... https://www.thehackerwire.com/vulnerability/CVE-2026-0704/ https://t.co/uvJU70adS1

    Post summary

    The post announces that CVE‑2026‑0704 is a critical flaw in Octopus Deploy, allowing file removal through an unvalidated API endpoint.

    0000042
    119 followersView on X
  • NerdieNews@NewsNerdie
    Active Exploitation

    Today's Top Cybersecurity News – February 26, 2026 1. CVE-2026-3057: SQL Injection in pearProjectApi Backend Task.php dateTotalForProject A remote SQL injection vulnerability exists in the dateTotalForProject function of pearProjectApi up to version 2.8.10, allowing attackers to manipulate the projectCode argument. The exploit is publicly available, increasing the risk of unauthorized data access or modification. Sources: Cvefeed https://cvefeed.io/vuln/detail/CVE-2026-3057 2. Critical Authentication Bypass and Privilege Escalation Vulnerabilities in Cisco Catalyst SD-WAN Multiple critical vulnerabilities in Cisco Catalyst SD-WAN products allow unauthenticated remote attackers to bypass authentication, escalate privileges to admin or root, and take full control of affected devices. Notably, CVE-2026-20127 has been actively exploited in zero-day attacks since 2023, enabling attackers to compromise controllers and insert rogue peers into networks. Users are urged to identify vulnerable devices, collect forensic data, update to patched versions, and conduct threat hunting. Sources: Bleepingcomputer, Cvefeed, Cyberscoop, Feedburner, Gbhackers, Kyberturvallisuuskeskus, Rapid7, Talosintelligence, Therecord https://www.kyberturvallisuuskeskus.fi/fi/kriittisia-haavoittuvuuksia-cisco-catalyst-sd-wan-tuotteissa 3. Multiple Critical and High Vulnerabilities Found in Binardat 10G08-0800GSM Network Switch A series of critical and high-severity vulnerabilities have been identified in Binardat 10G08-0800GSM network switch firmware versions prior to V300SP10260209. These include hard-coded credentials, predictable session IDs, plaintext password exposure, weak encryption, and command injection, exposing devices to unauthorized access, credential compromise, and remote code execution. Medium-severity issues such as missing login rate limiting, CSRF, and XSS further increase the attack surface. Sources: Bleepingcomputer, Cvefeed, Securityweek https://cvefeed.io/vuln/detail/CVE-2026-27521 4. Multiple Vulnerabilities Disclosed Including Critical Path Traversal in Local Path Provisioner Several security vulnerabilities were disclosed affecting various platforms including Octopus Deploy, Red Hat Developer Hub, openSUSE, Udisks, Rancher CLI, and Local Path Provisioner. Notably, a critical path traversal vulnerability in Local Path Provisioner allows attackers to overwrite sensitive files, while other issues range from denial of service to unauthorized access of encryption metadata. Sources: Cvefeed https://cvefeed.io/vuln/detail/CVE-2026-0704 5. Multiple Critical Vulnerabilities in FreeRDP Affecting Versions Prior to 3.23.0 FreeRDP versions before 3.23.0 contain multiple severe vulnerabilities including heap-use-after-free, out-of-bounds writes, integer overflow, and denial-of-service flaws. These issues can lead to client or server crashes, memory corruption, and potential remote code execution, especially when interacting with malicious RDP servers or crafted data. A patch addressing all these vulnerabilities is available in version 3.23.0. Sources: Cvefeed https://cvefeed.io/vuln/detail/CVE-2026-27951 Stay sharp. Stay secure. #NerdieNews #InfoSec #CyberSecurity #TechNews #DataSecurity #CyberThreats

    Post summary

    The post reports several critical vulnerabilities, notably an actively exploited Cisco SD‑WAN flaw (CVE‑2026‑20127), and provides patch information and detailed technical descriptions for multiple CVEs.

    0000037
    54 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-0704 In affected version of Octopus Deploy it was possible to remove files and/or contents of files on the host using an API endpoint. The field lacked validation which coul… https://www.cve.org/CVERecord?id=CVE-2026-0704

    Post summary

    The text announces CVE-2026-0704, describing a file deletion vulnerability in Octopus Deploy caused by missing validation on an API endpoint.

    0000069
    56.6K followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSmicrosoftwindows---
Appoctopusoctopus_server---

Explore more