Dell System Update flaw CVE-2026-86360 grants root access
Dell is urging customers to patch a critical vulnerability in the command-line interface (CLI) deployment tool of Dell System Update (DSU). The flaw could let a remote attacker run code with root privileges on unpatched systems.
The bug is tracked as CVE-2026-86360. Dell disclosed it in a security advisory published on Thursday, along with fixes for four other high-severity DSU flaws.
What DSU does and why it matters
DSU is an enterprise tool for IT administrators. They use it to push BIOS, firmware and software updates to Linux and Windows systems running on Dell's PowerEdge server infrastructure.
Because the tool sits close to the hardware and operating system of production servers, a flaw in it is serious. An attacker who abuses it is not just gaining access to one application. They could take over the server underneath it.
A path traversal bug with root-level impact
According to Dell, CVE-2026-86360 is a path traversal weakness. This class of bug lets an attacker reach files and directories outside the locations an application is supposed to access.
"An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access for [an] attacker," Dell said in its advisory.
The company explained why it rated the issue as critical. "This vulnerability is considered critical because it can be leveraged by an unauthenticated attacker to execute arbitrary code with root privileges. Successful exploitation may allow complete compromise of the vulnerable application and underlying operating system."
Two details stand out. The attacker does not need to log in, and the end result is root access, the highest level of control on a system.
Four more DSU flaws fixed
The same release addresses four high-severity issues in Dell System Update:
- CVE-2026-63697 and CVE-2026-71168, which remote attackers could use to achieve remote code execution
- CVE-2026-86361 and CVE-2026-86362, which could be abused for privilege escalation
"Dell recommends customers upgrade at the earliest opportunity," the company said. Administrators should move to DSU version 2.3.0.0 or later, which contains the fixes for all five flaws.
On the same day, Dell also asked IT teams to patch two maximum-severity vulnerabilities in its Container Storage Modules (CSM), tracked as CVE-2026-63688 and CVE-2026-63692.
An "unforgivable" class of bug
Path traversal flaws are well understood, and US authorities have been pushing vendors to eliminate them for some time. Since May 2024, the FBI and the US Cybersecurity and Infrastructure Security Agency (CISA), the federal agency responsible for protecting civilian government networks and critical infrastructure, have called on software makers to remove these weaknesses before products ship.
In that guidance, the agencies noted that such issues "have been called 'unforgivable' since at least 2007."
No exploitation reported yet, but Dell bugs have been targeted before
Dell has not marked any of the newly patched flaws as actively exploited. Still, state-backed hackers have abused Dell vulnerabilities in the past.
North Korea's Lazarus group exploited CVE-2021-21551, an insufficient access control flaw in Dell's dbutil driver, to deploy a Windows rootkit on victims' machines.
A more recent case was disclosed in February. Mandiant and the Google Threat Intelligence Group (GTIG) reported that suspected Chinese cyber spies, tracked as UNC6201, had been exploiting CVE-2026-22769 in Dell RecoverPoint for Virtual Machines since at least mid-2024. The flaw was a hardcoded credential. The attackers used it to create hidden network interfaces on VMware ESXi servers and to deploy malware.
The researchers also found overlaps between UNC6201 and Silk Typhoon, a Chinese cyberespionage group known for hitting government agencies with its custom Zipline and Spawnant malware in attacks that exploited Ivanti zero-days.
A few days after that report, CISA ordered federal agencies to patch vulnerable Dell systems on their networks within three days.
The Bigger Picture
For organisations running PowerEdge servers, the practical advice is simple: find every system where DSU is installed and update it to 2.3.0.0 or later. Since the critical flaw requires no authentication, it is also worth checking whether these management tools are reachable from networks that do not need access to them.
The broader context suggests this should not wait. Server management and update tooling is attractive to attackers because it runs with high privileges and is often trusted implicitly. The RecoverPoint case shows that a Dell flaw can be used quietly for a long time before anyone notices. Recent campaigns against other enterprise infrastructure, such as the NetScaler zero-day tied to state hackers, point to the same pattern of well-resourced groups focusing on edge and management systems.
The patch gap also matters. As vulnerability disclosures rise and exploitation speeds up, the time between an advisory and the first attacks may keep shrinking. A publicly documented path traversal bug with root impact could be an easy target for anyone who compares patched and unpatched versions.
It is also notable that a basic bug class, one US authorities have publicly labelled as avoidable, still turns up in a critical enterprise tool in 2026. This suggests secure-by-design commitments have yet to fully reach every product line.
What to watch next: whether Dell or CISA later reports exploitation of CVE-2026-86360 or the related flaws, and whether CISA adds any of them to its list of known exploited vulnerabilities. That would bring firm patch deadlines for US federal agencies.
