Skip to content

Security1 publisher3 min readPublished

Dell patches unauthenticated root flaw CVE-2026-86360 in its PowerEdge update tool

Dell has fixed CVE-2026-86360, a critical path traversal in Dell System Update that lets an unauthenticated remote attacker run code as root. Any server on a DSU build older than 2.3.0.0 stays exposed until it is updated.

The Watch · Security desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Illustration accompanying Dell patches unauthenticated root flaw CVE-2026-86360 in its PowerEdge update tool
Generated illustration

What happened

  • DSU is Dell's command-line tool for pushing BIOS, firmware and software updates onto Linux and Windows systems across PowerEdge server infrastructure.
  • The same Thursday release fixed four high-severity DSU flaws, two allowing remote code execution and two allowing privilege escalation.
  • Dell has not flagged any of the flaws it fixed that day as actively exploited.
  • Dell also told administrators that day to patch two maximum-severity flaws in its Container Storage Modules, CVE-2026-63688 and CVE-2026-63692.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure Root through the update tool puts an attacker in the same position administrators use to push BIOS and firmware changes onto that server.
  • decision One DSU release closes three remote code execution paths, so deferring it to a scheduled window leaves every older, reachable host with more than one way in.
  • precedent If exploitation of DSU surfaces, the RecoverPoint case sets the expectation of a federal patch deadline measured in days.

Dell's advisory describes the attack in two steps. A path traversal gives a remote attacker access to the filesystem, and Dell says that access can be turned into code running as root [3]. According to Dell, an unauthenticated attacker with remote access could potentially exploit the vulnerability to gain filesystem access [4]. In the same advisory the company said: "This vulnerability is considered critical because it can be leveraged by an unauthenticated attacker to execute arbitrary code with root privileges. Successful exploitation may allow complete compromise of the vulnerable application and underlying operating system." [5]

For exploitability, few bug profiles rate worse than an unauthenticated remote flaw that ends in root code execution. Dell's own wording still hedges, with "could potentially" and "may" [4][5]. BleepingComputer's report does not say which DSU component accepts remote input, or whether one compromised instance can reach other servers. On the published evidence, exposure is counted host by host: every system running a DSU build older than 2.3.0.0 [8].

Older builds have more than one remote path in. Version 2.3.0.0 fixes five DSU flaws [15]. Three of them allow remote code execution: the critical bug plus CVE-2026-63697 and CVE-2026-71168 [16][7]. The other two, CVE-2026-86361 and CVE-2026-86362, are privilege escalation bugs [7]. Dell first told customers to patch as soon as possible [1]. "Dell recommends customers upgrade at the earliest opportunity," the company said [8].

Path traversal is an old bug class. The FBI and CISA have urged software makers since May 2024 to remove path traversal weaknesses before shipping, saying such issues "have been called 'unforgivable' since at least 2007" [6].

State-backed attackers have used flaws in Dell software before. North Korea's Lazarus group exploited CVE-2021-21551, an insufficient access control flaw in the Dell dbutil driver, to plant a Windows rootkit [11]. In February, Mandiant and the Google Threat Intelligence Group reported that suspected Chinese spies tracked as UNC6201 had exploited CVE-2026-22769, a hardcoded credential in Dell RecoverPoint for Virtual Machines, since at least mid-2024 [12]. The group used it to create hidden network interfaces on VMware ESXi servers and deploy malware [12]. The researchers found overlaps between UNC6201 and Silk Typhoon, a group linked to the Zipline and Spawnant malware seen in attacks exploiting Ivanti zero-days [13]. A few days after that, CISA gave federal agencies three days to patch their vulnerable Dell systems [14].

Those are two actors working two different products [11][12]. Together they show sustained interest in Dell's enterprise software. In the RecoverPoint case the flaw was in use from at least mid-2024 until the February report [12]. In my view that history, together with three remote code execution paths in a single tool, justifies moving DSU 2.3.0.0 ahead of the next maintenance window [16].

What to watch

  • Technical detail from Dell or researchers on which DSU component accepts remote input, which would set how many servers an attacker can actually reach.
  • Any report from Dell or CISA that CVE-2026-86360 or the two high-severity DSU code execution bugs are being exploited, and whether CISA attaches a deadline like its three-day Dell order.
  • A public proof-of-concept for the path traversal, which would shorten the time between disclosure and attacks.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories