DKDKCISSPSearch
VulnerabilitiesDEVELOPING

Dell System Update flaw allows attackers to gain root privileges (CVE-2026-86360) - Help Net Security

Dell is urging customers to patch a vulnerability (CVE-2026-86360) in Dell System Update (DSU) that could allow an unauthenticated remote attacker to execute arbitrary code with root privileges.

DKCISSP News DeskHelp Net Security6 Oct 2026, 4:14 pm
Dell System Update flaw allows attackers to gain root privileges (CVE-2026-86360) - Help Net Security
Image courtesy of Help Net Security. Original report
DKCISSP REPORT

Dell is urging customers to patch a vulnerability (CVE-2026-86360) in Dell System Update (DSU) that could allow an unauthenticated remote attacker to execute arbitrary code with root privileges.

In a Thursday security advisory, the company said the flaw (tracked as CVE-2026-86360) allows threat actors to execute code with root privileges on unpatched devices by exploiting a path traversal weakness.

Cybersecurity and Infrastructure Security Agency (CISA) have urged software companies since May 2024 to remove path traversal weaknesses from their products before shipping, saying such security issues "have been called 'unforgivable' since at least 2007." Dell also patched four high-severity Dell System Update security flaws on Thursday, two that remote attackers can exploit to gain remote code execution (CVE-2026-63697 and CVE-2026-71168) and two more that can be abused for privilege escalation (CVE-2026-86361 and CVE-2026-86362).

Ori Gabriel reported CVE-2026-86360 and CVE-2026-63697.

CVE-2026-86360 is a path traversal vulnerability with a CVSS base score of 9.6 that affects DSU versions before 2.3.0.0.

More recently, Mandiant and the Google Threat Intelligence Group (GTIG) revealed in February that suspected Chinese cyber spies (tracked as UNC6201) had been exploiting a hardcoded-credential vulnerability (CVE-2026-22769) in Dell RecoverPoint for Virtual Machines since at least mid-2024 to create hidden network interfaces on VMware ESXi servers and deploy malware payloads.

Two of them (CVE-2026-63697 and CVE-2026-71168) could lead to remote execution, and the other two (CVE-2026-86361 and CVE-2026-86362) could let attackers elevate their privileges.

This vulnerability is considered critical because it can be leveraged by an unauthenticated attacker to execute arbitrary code with root privileges,” the company wrote in the advisory.

A researcher using the name saltedfish reported CVE-2026-86361 and CVE-2026-86362, and Nir Yehoshua of Cipher Security Labs reported CVE-2026-71168.

Dell warned customers to patch a critical vulnerability in the System Update (DSU) command-line interface (CLI) deployment tool as soon as possible.

What happened

Dell is urging customers to patch a vulnerability (CVE-2026-86360) in Dell System Update (DSU) that could allow an unauthenticated remote attacker to execute arbitrary code with root privileges.

In a Thursday security advisory, the company said the flaw (tracked as CVE-2026-86360) allows threat actors to execute code with root privileges on unpatched devices by exploiting a path traversal weakness.

What changed

Cybersecurity and Infrastructure Security Agency (CISA) have urged software companies since May 2024 to remove path traversal weaknesses from their products before shipping, saying such security issues "have been called 'unforgivable' since at least 2007." Dell also patched four high-severity Dell System Update security flaws on Thursday, two that remote attackers can exploit to gain remote code execution (CVE-2026-63697 and CVE-2026-71168) and two more that can be abused for privilege escalation (CVE-2026-86361 and CVE-2026-86362).

Ori Gabriel reported CVE-2026-86360 and CVE-2026-63697.

Who is affected

CVE-2026-86360 is a path traversal vulnerability with a CVSS base score of 9.6 that affects DSU versions before 2.3.0.0.

More recently, Mandiant and the Google Threat Intelligence Group (GTIG) revealed in February that suspected Chinese cyber spies (tracked as UNC6201) had been exploiting a hardcoded-credential vulnerability (CVE-2026-22769) in Dell RecoverPoint for Virtual Machines since at least mid-2024 to create hidden network interfaces on VMware ESXi servers and deploy malware payloads.

Why it matters

Two of them (CVE-2026-63697 and CVE-2026-71168) could lead to remote execution, and the other two (CVE-2026-86361 and CVE-2026-86362) could let attackers elevate their privileges.

This vulnerability is considered critical because it can be leveraged by an unauthenticated attacker to execute arbitrary code with root privileges,” the company wrote in the advisory.

Technical details

A researcher using the name saltedfish reported CVE-2026-86361 and CVE-2026-86362, and Nir Yehoshua of Cipher Security Labs reported CVE-2026-71168.

Dell warned customers to patch a critical vulnerability in the System Update (DSU) command-line interface (CLI) deployment tool as soon as possible.

According to Dell, successful exploitation may lead to complete compromise of the vulnerable application and the underlying operating system.

Response

That same day, Dell also urged IT administrators to patch two maximum-severity Container Storage Modules (CSM) vulnerabilities (CVE-2026-63688 and CVE-2026-63692) as soon as possible.

Days later, CISA ordered federal agencies to patch vulnerable Dell systems on their networks within three days.

What security teams should do

DSU is a tool used by enterprise IT administrators to apply driver, BIOS, and firmware updates to Dell PowerEdge servers.

DSU lets enterprise IT administrators deploy BIOS, firmware, and software updates onto Linux and Windows systems on PowerEdge enterprise server infrastructure.

Attribution

Help Net Security: Dell is urging customers to patch a vulnerability (CVE-2026-86360) in Dell System Update (DSU) that could allow an unauthenticated remote attacker to execute arbitrary code with root privileges.

BleepingComputer: Dell warned customers to patch a critical vulnerability in the System Update (DSU) command-line interface (CLI) deployment tool as soon as possible.

What to watch next

Watch for updated vendor guidance and fixed-version details.

MORE IN VULNERABILITIES

More cybersecurity reporting

Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCEThe Hacker News · 5 Oct 2026, 8:48 pmOut-of-band Exchange Server update fixes high-severity mailbox access bug (CVE-2026-96940) - Help Net SecurityHelp Net Security · 5 Oct 2026, 4:08 pmAttackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOTThe Hacker News · 5 Oct 2026, 1:00 pmCVE-2023-36025 (SmartScreen Bypass) Vulnerability: Analysis & Detection | HuntressHuntress · 4 Oct 2026, 5:30 am