Dell is urging customers to patch a critical vulnerability in the command-line interface (CLI) deployment tool of Dell System Update (DSU). The flaw could let a remote attacker run code with root privileges on unpatched systems.
The bug is tracked as CVE-2026-86360. Dell disclosed it in a security advisory published on Thursday, along with fixes for four other high-severity DSU flaws.
What DSU does and why it matters
DSU is an enterprise tool for IT administrators. They use it to push BIOS, firmware and software updates to Linux and Windows systems running on Dell's PowerEdge server infrastructure.
Dell has fixed two maximum severity vulnerabilities in Container Storage Modules (CSM), the software that links the company's enterprise storage arrays to Kubernetes environments. The company is urging customers to update as soon as possible.
CSM works with Dell's main storage platforms, including PowerStore, PowerScale, PowerFlex, PowerMax and Unity XT. It adds features on top of the standard Container Storage Interface (CSI) drivers, which Kubernetes uses to talk to external storage systems.
Two critical flaws in the Authorization module
According to a security advisory Dell published on Thursday, both flaws sit in the CSM Authorization security module. Dell traces both to the same type of weakness: "missing authentication for critical functions."
Guy Fawkes News is financed by advertising. You can choose how you want to use this website:
With advertising: we load an advertising script from a third-party ad network. The ad network may set cookies, use your IP address and device information, and may process data outside the EU. We also count your visits for our own visitor statistics (with a random ID stored in your browser).
Ad-free for €0.99 per month: no advertising and no advertising tracking. Cancel at any time.
You can change your decision at any time via "Cookie Settings" at the bottom of every page.