Dell warns customers to patch critical System Update vulnerability
Dell is urging customers to patch a critical vulnerability in its Dell System Update (DSU) command-line interface (CLI) deployment tool as soon as possible.
DSU enables enterprise IT administrators to deploy BIOS, firmware, and software updates to Linux and Windows systems running on PowerEdge enterprise server infrastructure.
Critical Dell flaw enables root-level code execution
Tracked as CVE-2026-86360, the vulnerability is caused by a path traversal weakness that could allow an attacker to access the file system and execute code with root privileges on an unpatched device.
Dell said in a security advisory published Thursday that an unauthenticated attacker with remote access could exploit the flaw to gain access to the file system.
“This vulnerability is considered critical because it could be exploited by an unauthenticated attacker to execute arbitrary code with root privileges,” Dell said. “Successful exploitation could result in complete compromise of the vulnerable application and the underlying operating system.”
Starting in May 2024, the FBI and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) have required software companies to remove path traversal weaknesses from their products before shipping. The agencies said these security issues have been called “unforgivable” since at least 2007.
Dell patches four additional DSU vulnerabilities
Dell also patched four high-severity vulnerabilities in Dell System Update. Two of the flaws, CVE-2026-63697 and CVE-2026-71168, could allow remote code execution. The other two, CVE-2026-86361 and CVE-2026-86362, could be exploited for privilege escalation.
Dell recommends that customers upgrade at the earliest opportunity to Dell System Update (DSU) 2.3.0.0 or later, which patches the critical vulnerability.
Dell urges customers to patch Container Storage Module flaws
On the same day, Dell also urged IT administrators to patch two maximum-severity vulnerabilities in its Container Storage Module (CSM). The flaws are tracked as CVE-2026-63688 and CVE-2026-63692.
Dell has not reported that the vulnerabilities are being actively exploited. However, state-sponsored hacking groups have exploited other Dell vulnerabilities in attacks in recent years.
State-backed hackers have targeted Dell vulnerabilities
North Korea’s Lazarus hacking group previously exploited an insufficient access control vulnerability in the Dell dbutil driver, tracked as CVE-2021-21551, to deploy a Windows rootkit on victim systems.
More recently, Mandiant and Google Threat Intelligence Group (GTIG) reported in February that a suspected Chinese cyber-espionage group tracked as UNC6201 had been exploiting hardcoded credentials in Dell RecoverPoint for Virtual Machines, tracked as CVE-2026-22769.
The group reportedly used the vulnerability to create hidden network interfaces on VMware ESXi servers and deploy malware, with activity dating back to at least mid-2024.
Researchers also found overlap between UNC6201 and Silk Typhoon, a Chinese cyber-espionage group known for targeting government agencies with custom Zipline and Spawnant malware in Ivanti zero-day attacks.
Days later, CISA ordered federal agencies to patch vulnerable Dell systems on their networks within three days.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a two-hour digital summit about what will change with AI-speed attacks, what defenders should stop doing, and how to verify, decide, fix, and revalidate at machine speed.
Source: www.bleepingcomputer.com



