Dell is warning customers to patch a critical vulnerability in its System Update (DSU) command-line interface deployment tool as soon as possible. The DSU tool is used by enterprise IT administrators to deploy BIOS, firmware, and software updates on Linux and Windows systems running on PowerEdge enterprise server infrastructure. According to a Thursday security advisory from the company, the flaw tracked as CVE-2026-86360 lets threat actors run code with root privileges on unpatched devices by exploiting a path traversal weakness.
Dell said an unauthenticated attacker with remote access could potentially exploit the vulnerability, resulting in filesystem access for the attacker. The company classified the issue as critical because an unauthenticated attacker can use it to execute arbitrary code with root privileges, and successful exploitation may allow a complete compromise of the vulnerable application and the underlying operating system. The FBI and the U.S. Cybersecurity and Infrastructure Security Agency have urged software makers since May 2024 to eliminate path traversal weaknesses before shipping products, noting that such issues have been called unforgivable since at least 2007.
Dell also patched four high-severity Dell System Update flaws on Thursday. Two of them, CVE-2026-63697 and CVE-2026-71168, can be exploited by remote attackers to gain remote code execution, while CVE-2026-86361 and CVE-2026-86362 can be abused for privilege escalation. Dell recommends customers upgrade at the earliest opportunity and advised updating Dell System Update to version 2.3.0.0 or later, which patches the flaws.
The same day, Dell urged IT administrators to patch two maximum-severity Container Storage Modules vulnerabilities, CVE-2026-63688 and CVE-2026-63692, as soon as possible. Dell has not flagged any of these flaws as actively exploited.
State-backed hacking groups have abused other Dell vulnerabilities in attacks in recent years. The North Korean Lazarus hacking group deployed a Windows rootkit on victims' systems by exploiting an insufficient access control vulnerability, CVE-2021-21551, in the Dell dbutil driver.
More recently, Mandiant and the Google Threat Intelligence Group revealed in February that suspected Chinese cyber spies tracked as UNC6201 had been exploiting a hardcoded-credential vulnerability, CVE-2026-22769, in Dell RecoverPoint for Virtual Machines since at least mid-2024 to create hidden network interfaces on VMware ESXi servers and deploy malware payloads. They also found overlaps between UNC6201 and the Silk Typhoon Chinese cyberespionage group, known for targeting government agencies with custom Zipline and Spawnant malware in Ivanti zero-day attacks. Days later, CISA ordered federal agencies to patch vulnerable Dell systems on their networks within three days.
More cybersecurity news from TechManNews.








