Dell's Thursday patch closes a root-level DSU flaw
Dell patched CVE-2026-86360, a path traversal flaw in the System Update CLI that gives unauthenticated remote attackers root. Upgrade to DSU 2.3.0.0.
Dell is telling customers to patch CVE-2026-86360, a path traversal bug in the System Update (DSU) command-line tool that lets an unauthenticated remote attacker execute arbitrary code as root. The fix shipped Thursday, and the upgrade target is DSU 2.3.0.0 or later.
DSU is the CLI that enterprise IT teams use to push BIOS, firmware, and software updates to Linux and Windows hosts on PowerEdge server infrastructure. That placement is what makes the bug worth attention. The tool already runs with the privileges needed to rewrite firmware across a fleet, so code execution inside it lands at root on the machine doing the deploying.
Dell’s advisory describes the entry point plainly: “An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access for [an] attacker.” The company rates it critical because “it can be leveraged by an unauthenticated attacker to execute arbitrary code with root privileges,” and says successful exploitation “may allow complete compromise of the vulnerable application and underlying operating system.”
A path traversal weakness shipping in a 2026 release is exactly the kind of thing CISA has been complaining about. The FBI and CISA have pushed software vendors since May 2024 to clear path traversal flaws from their products before they ship, pointing out that the class has been called “unforgivable” since at least 2007.
The same release cleans up four more DSU flaws rated high severity: two that allow remote code execution (CVE-2026-63697 and CVE-2026-71168) and two privilege escalation bugs (CVE-2026-86361 and CVE-2026-86362). DSU 2.3.0.0 covers all five, and Dell recommends upgrading at the earliest opportunity.
Dell also pushed two maximum-severity fixes the same day for its Container Storage Modules (CVE-2026-63688 and CVE-2026-63692), with the same instruction to patch as soon as possible.
None of these are flagged as actively exploited yet. That is cold comfort given who has gone after Dell software before. The North Korean Lazarus group used an insufficient access control bug in the Dell dbutil driver (CVE-2021-21551) to drop a Windows rootkit on victims’ systems. More recently, Mandiant and the Google Threat Intelligence Group reported in February that a suspected Chinese group tracked as UNC6201 had been exploiting a hardcoded-credential vulnerability (CVE-2026-22769) in Dell RecoverPoint for Virtual Machines since at least mid-2024, using it to stand up hidden network interfaces on VMware ESXi servers and deploy malware. GTIG found overlaps between UNC6201 and Silk Typhoon, the Chinese espionage group known for custom Zipline and Spawnant malware in Ivanti zero-day attacks. Days after that disclosure, CISA ordered federal agencies to patch the affected Dell systems on their networks within three days.
Keep Reading
gitlabGitLab AI Gateway sandbox escape
GitLab's critical CVE-2026-90970 lets an authenticated Duo user escape the AI Gateway prompt sandbox and run arbitrary commands. Self-hosted operators must patch now.
kiteworksKiteworks patches max-severity EPG flaw in Wednesday advisory
Kiteworks patched CVE-2026-54154, a max-severity unauthenticated RCE in its Email Protection Gateway. Upgrade to 9.4.1 and check exposed appliances.
vulnerabilityMath.random() session key lets attackers run code on HFS
A weak Math.random() session key in Rejetto HFS 3.0.0-3.2.0 lets attackers forge admin cookies and run code; CVE-2026-61500 is under active exploitation.
Latest on the Wire
Full wire →- 5.3M-year-old whale necropolis discovered in deep seaHacker News
- ADHD Linked to Circadian Rhythm Disruption: Evidence and ChronotherapyHacker News
- AhsayCBS Flaws Exploited for Webshells, Crypto MiningBleepingComputer
- AI Won't Replace Programmers but Will Change the RoleHacker News
New signal daily · RSS
Stay in the loop
New writing delivered when it's ready. No schedule, no spam.