Dell System Update flaw allows attackers to gain root privileges (CVE-2026-86360) - Help Net Security
Dell is urging customers to patch a vulnerability (CVE-2026-86360) in Dell System Update (DSU) that could allow an unauthenticated remote attacker to execute arbitrary code with root privileges.

Dell is urging customers to patch a vulnerability (CVE-2026-86360) in Dell System Update (DSU) that could allow an unauthenticated remote attacker to execute arbitrary code with root privileges.
In a Thursday security advisory, the company said the flaw (tracked as CVE-2026-86360) allows threat actors to execute code with root privileges on unpatched devices by exploiting a path traversal weakness.
Cybersecurity and Infrastructure Security Agency (CISA) have urged software companies since May 2024 to remove path traversal weaknesses from their products before shipping, saying such security issues "have been called 'unforgivable' since at least 2007." Dell also patched four high-severity Dell System Update security flaws on Thursday, two that remote attackers can exploit to gain remote code execution (CVE-2026-63697 and CVE-2026-71168) and two more that can be abused for privilege escalation (CVE-2026-86361 and CVE-2026-86362).
Ori Gabriel reported CVE-2026-86360 and CVE-2026-63697.
CVE-2026-86360 is a path traversal vulnerability with a CVSS base score of 9.6 that affects DSU versions before 2.3.0.0.
More recently, Mandiant and the Google Threat Intelligence Group (GTIG) revealed in February that suspected Chinese cyber spies (tracked as UNC6201) had been exploiting a hardcoded-credential vulnerability (CVE-2026-22769) in Dell RecoverPoint for Virtual Machines since at least mid-2024 to create hidden network interfaces on VMware ESXi servers and deploy malware payloads.
Two of them (CVE-2026-63697 and CVE-2026-71168) could lead to remote execution, and the other two (CVE-2026-86361 and CVE-2026-86362) could let attackers elevate their privileges.
This vulnerability is considered critical because it can be leveraged by an unauthenticated attacker to execute arbitrary code with root privileges,” the company wrote in the advisory.
A researcher using the name saltedfish reported CVE-2026-86361 and CVE-2026-86362, and Nir Yehoshua of Cipher Security Labs reported CVE-2026-71168.
Dell warned customers to patch a critical vulnerability in the System Update (DSU) command-line interface (CLI) deployment tool as soon as possible.
What happened
Dell is urging customers to patch a vulnerability (CVE-2026-86360) in Dell System Update (DSU) that could allow an unauthenticated remote attacker to execute arbitrary code with root privileges.
In a Thursday security advisory, the company said the flaw (tracked as CVE-2026-86360) allows threat actors to execute code with root privileges on unpatched devices by exploiting a path traversal weakness.
What changed
Cybersecurity and Infrastructure Security Agency (CISA) have urged software companies since May 2024 to remove path traversal weaknesses from their products before shipping, saying such security issues "have been called 'unforgivable' since at least 2007." Dell also patched four high-severity Dell System Update security flaws on Thursday, two that remote attackers can exploit to gain remote code execution (CVE-2026-63697 and CVE-2026-71168) and two more that can be abused for privilege escalation (CVE-2026-86361 and CVE-2026-86362).
Ori Gabriel reported CVE-2026-86360 and CVE-2026-63697.
Who is affected
CVE-2026-86360 is a path traversal vulnerability with a CVSS base score of 9.6 that affects DSU versions before 2.3.0.0.
More recently, Mandiant and the Google Threat Intelligence Group (GTIG) revealed in February that suspected Chinese cyber spies (tracked as UNC6201) had been exploiting a hardcoded-credential vulnerability (CVE-2026-22769) in Dell RecoverPoint for Virtual Machines since at least mid-2024 to create hidden network interfaces on VMware ESXi servers and deploy malware payloads.
Why it matters
Two of them (CVE-2026-63697 and CVE-2026-71168) could lead to remote execution, and the other two (CVE-2026-86361 and CVE-2026-86362) could let attackers elevate their privileges.
This vulnerability is considered critical because it can be leveraged by an unauthenticated attacker to execute arbitrary code with root privileges,” the company wrote in the advisory.
Technical details
A researcher using the name saltedfish reported CVE-2026-86361 and CVE-2026-86362, and Nir Yehoshua of Cipher Security Labs reported CVE-2026-71168.
Dell warned customers to patch a critical vulnerability in the System Update (DSU) command-line interface (CLI) deployment tool as soon as possible.
According to Dell, successful exploitation may lead to complete compromise of the vulnerable application and the underlying operating system.
Response
That same day, Dell also urged IT administrators to patch two maximum-severity Container Storage Modules (CSM) vulnerabilities (CVE-2026-63688 and CVE-2026-63692) as soon as possible.
Days later, CISA ordered federal agencies to patch vulnerable Dell systems on their networks within three days.
What security teams should do
DSU is a tool used by enterprise IT administrators to apply driver, BIOS, and firmware updates to Dell PowerEdge servers.
DSU lets enterprise IT administrators deploy BIOS, firmware, and software updates onto Linux and Windows systems on PowerEdge enterprise server infrastructure.
Attribution
Help Net Security: Dell is urging customers to patch a vulnerability (CVE-2026-86360) in Dell System Update (DSU) that could allow an unauthenticated remote attacker to execute arbitrary code with root privileges.
BleepingComputer: Dell warned customers to patch a critical vulnerability in the System Update (DSU) command-line interface (CLI) deployment tool as soon as possible.
What to watch next
Watch for updated vendor guidance and fixed-version details.