RC RANDOM CHAOS

Dell's Thursday patch closes a root-level DSU flaw

Dell patched CVE-2026-86360, a path traversal flaw in the System Update CLI that gives unauthenticated remote attackers root. Upgrade to DSU 2.3.0.0.

· 2 min read
Dell's Thursday patch closes a root-level DSU flaw

Dell is telling customers to patch CVE-2026-86360, a path traversal bug in the System Update (DSU) command-line tool that lets an unauthenticated remote attacker execute arbitrary code as root. The fix shipped Thursday, and the upgrade target is DSU 2.3.0.0 or later.

DSU is the CLI that enterprise IT teams use to push BIOS, firmware, and software updates to Linux and Windows hosts on PowerEdge server infrastructure. That placement is what makes the bug worth attention. The tool already runs with the privileges needed to rewrite firmware across a fleet, so code execution inside it lands at root on the machine doing the deploying.

Dell’s advisory describes the entry point plainly: “An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access for [an] attacker.” The company rates it critical because “it can be leveraged by an unauthenticated attacker to execute arbitrary code with root privileges,” and says successful exploitation “may allow complete compromise of the vulnerable application and underlying operating system.”

A path traversal weakness shipping in a 2026 release is exactly the kind of thing CISA has been complaining about. The FBI and CISA have pushed software vendors since May 2024 to clear path traversal flaws from their products before they ship, pointing out that the class has been called “unforgivable” since at least 2007.

The same release cleans up four more DSU flaws rated high severity: two that allow remote code execution (CVE-2026-63697 and CVE-2026-71168) and two privilege escalation bugs (CVE-2026-86361 and CVE-2026-86362). DSU 2.3.0.0 covers all five, and Dell recommends upgrading at the earliest opportunity.

Dell also pushed two maximum-severity fixes the same day for its Container Storage Modules (CVE-2026-63688 and CVE-2026-63692), with the same instruction to patch as soon as possible.

None of these are flagged as actively exploited yet. That is cold comfort given who has gone after Dell software before. The North Korean Lazarus group used an insufficient access control bug in the Dell dbutil driver (CVE-2021-21551) to drop a Windows rootkit on victims’ systems. More recently, Mandiant and the Google Threat Intelligence Group reported in February that a suspected Chinese group tracked as UNC6201 had been exploiting a hardcoded-credential vulnerability (CVE-2026-22769) in Dell RecoverPoint for Virtual Machines since at least mid-2024, using it to stand up hidden network interfaces on VMware ESXi servers and deploy malware. GTIG found overlaps between UNC6201 and Silk Typhoon, the Chinese espionage group known for custom Zipline and Spawnant malware in Ivanti zero-day attacks. Days after that disclosure, CISA ordered federal agencies to patch the affected Dell systems on their networks within three days.

Share

Keep Reading

Latest on the Wire

Full wire →

New signal daily · RSS

Stay in the loop

New writing delivered when it's ready. No schedule, no spam.