Dell Warns New System Update Has a Critical Flaw That Could Give Hackers Root Access
Dell has urged its customers to update its Dell System Update (DSU) software after discovering a critical security vulnerability that could allow attackers to execute arbitrary code with root privileges on vulnerable systems. The flaw affects DSU versions older than 2.3.0.0 and carries a CVSS score of 9.6.
The Dell System Update flaw can lead to complete system compromise
Tracked as CVE-2026-86360, the vulnerability is a path traversal flaw that can be exploited by an unauthenticated attacker with remote access. Successful exploitation can provide filesystem access and allow arbitrary code execution with root privileges, potentially resulting in complete compromise of the affected application and underlying operating system.
Dell System Update is used by enterprise IT administrators to deploy BIOS, firmware and software updates on Linux and Windows systems, including PowerEdge server infrastructure. That makes the vulnerability especially concerning for organizations managing large numbers of Dell systems.
Dell has also patched four additional high-severity DSU vulnerabilities. Two of them can be exploited for remote code execution, while the other two can allow attackers to escalate privileges. These are tracked as CVE-2026-63697, CVE-2026-71168, CVE-2026-86361 and CVE-2026-86362.
Dell recommends updating System Update immediately
Dell recommends customers upgrade to Dell System Update 2.3.0.0 or later. The company has not reported these vulnerabilities as actively exploited, but it is urging customers to apply the available update at the earliest opportunity.
The warning is worth taking seriously, especially for organizations running Dell PowerEdge infrastructure. Dell has previously had vulnerabilities exploited by state-backed threat actors, including attacks involving the Lazarus group and suspected Chinese cyberespionage activity.
via: Bleeping Computer
Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more
User forum
0 messages