The vulnerability, tracked as CVE-2026-86360, is a path traversal weakness in Dell System Update (DSU), a tool used by enterprise IT administrators to deploy BIOS, firmware, and software updates on Linux and Windows systems across PowerEdge server infrastructure. Dell said the flaw could allow an unauthenticated attacker with remote access to gain filesystem access and execute code with root privileges, potentially leading to complete compromise of the vulnerable application and underlying operating system.
Dell has advised customers to update DSU to version 2.3.0.0 or later at the earliest opportunity. The same advisory also patched four high-severity issues: two that could enable remote code execution (CVE-2026-63697 and CVE-2026-71168) and two that could be abused for privilege escalation (CVE-2026-86361 and CVE-2026-86362).
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the FBI have since last year urged software vendors to eliminate path traversal vulnerabilities before shipping, describing such security holes as "unforgivable" since at least 2007.
While Dell has not reported active exploitation of these particular flaws, the company noted that state-backed hacking groups have abused other Dell vulnerabilities in recent years. In February, Mandiant and Google Threat Intelligence Group revealed that suspected Chinese cyber spies (UNC6201) had been exploiting a hardcoded-credential vulnerability in Dell RecoverPoint for Virtual Machines since mid-2024. The North Korean Lazarus group has also exploited a Dell driver bug to deploy rootkits.