
Dell warned customers to patch a critical vulnerability in the System Update (DSU) command-line interface (CLI) deployment tool as soon as possible.
DSU lets enterprise IT administrators deploy BIOS, firmware, and software updates onto Linux and Windows systems on PowerEdge enterprise server infrastructure.
In a Thursday security advisory, the company said the flaw (tracked as CVE-2026-86360) allows threat actors to execute code with root privileges on unpatched devices by exploiting a path traversal weakness.
"An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access for [an] attacker," the company Dell said. "This vulnerability is considered critical because it can be leveraged by an unauthenticated attacker to execute arbitrary code with root privileges. Successful exploitation may allow complete compromise of the vulnerable application and underlying operating system."
The FBI and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) have urged software companies since May 2024 to remove path traversal weaknesses from their products before shipping, saying such security issues "have been called 'unforgivable' since at least 2007."
Dell also patched four high-severity Dell System Update security flaws on Thursday, two that remote attackers can exploit to gain remote code execution (CVE-2026-63697 and CVE-2026-71168) and two more that can be abused for privilege escalation (CVE-2026-86361 and CVE-2026-86362).
"Dell recommends customers upgrade at the earliest opportunity," the company said, advising customers to update Dell System Update (DSU) to 2.3.0.0 or later, which patches the flaws.
That same day, Dell also urged IT administrators to patch two maximum-severity Container Storage Modules (CSM) vulnerabilities (CVE-2026-63688 and CVE-2026-63692) as soon as possible.
While Dell has not yet flagged any of these flaws as actively exploited, state-backed hacking groups have abused other Dell vulnerabilities in attacks in recent years.
For instance, the North Korean Lazarus hacking group deployed a Windows rootkit on victims' systems by exploiting an insufficient access control vulnerability (CVE-2021-21551) in the Dell dbutil driver.
More recently, Mandiant and the Google Threat Intelligence Group (GTIG) revealed in February that suspected Chinese cyber spies (tracked as UNC6201) had been exploiting a hardcoded-credential vulnerability (CVE-2026-22769) in Dell RecoverPoint for Virtual Machines since at least mid-2024 to create hidden network interfaces on VMware ESXi servers and deploy malware payloads.
They also found overlaps between UNC6201 and the Silk Typhoon Chinese cyberespionage group, which is known for targeting government agencies with custom Zipline and Spawnant malware in Ivanti zero-day attacks.
Days later, CISA ordered federal agencies to patch vulnerable Dell systems on their networks within three days.
Build your security blueprint for AI-powered attacks
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Save your seat