
if you run octopus server, today's check is cve-2026-92355: 1. inventory self-hosted servers and exact build numbers 2. find who can modify non-built-in external feeds 3. upgrade to 2026.1.11725, 2026.2.13344, or 2026.3.15816 for your branch 4. review recent feed changes and unexpected writes on the server 5. rotate credentials if a writable path held configs, scripts, or secrets a feed editor can traverse paths and overwrite arbitrary files. in some setups, that becomes remote code execution. 'can edit a package feed' is infrastructure access now. https://advisories.octopus.com/post/2026/sa2026-09/
