Dell patches a critical flaw in its server update tool that hands attackers root
A path traversal bug in Dell System Update, rated 9.6, lets an unauthenticated attacker take over the machine. Dell says upgrade to 2.3.0.0 now.

Key points
- Dell has patched a critical flaw, CVE-2026-86360, in its System Update tool that lets a remote attacker with no login take full control of a server, scored 9.6 out of 10.
- The fix is in Dell System Update version 2.3.0.0, released alongside the advisory on 5 October 2026.
- Four further high-severity bugs in the same tool were patched the same day, including CVE-2026-63697 and CVE-2026-71168.
- Dell says none of the new flaws are being exploited yet, but earlier Dell bugs have been abused by North Korean and suspected Chinese state hackers.
- US federal agencies were given just three days to patch an older Dell RecoverPoint flaw, CVE-2026-22769, after it was found in active use.
Dell has told customers to urgently update a tool used by IT staff to push software and firmware onto its servers, after researchers found a flaw that lets an outsider take the machine over completely.
The tool is Dell System Update, or DSU. Big companies use it to roll out BIOS updates and firmware patches across fleets of PowerEdge servers running Linux or Windows. If you run a data centre on Dell kit, this program is almost certainly on it.
The critical bug, tracked as CVE-2026-86360, is a path traversal weakness. The software fails to properly check where files are being read from or written to, so an attacker can trick it into touching parts of the filesystem it should never reach. Dell's advisory says an attacker with no username or password can exploit this remotely to run code as root, the highest level of access on the system. Fix it: upgrade DSU to version 2.3.0.0 or later.
What else did Dell patch?
Four other high-severity bugs in DSU were fixed the same day, alongside two maximum-severity flaws in a separate product called Container Storage Modules. Dell tells customers to apply all of them "at the earliest opportunity."
The two DSU bugs that sit closest to the critical one are worth calling out. CVE-2026-63697, scored 7.6, is an improper certificate validation flaw: the tool doesn't properly verify it's talking to the real Dell update service, which a remote attacker can exploit to run code. CVE-2026-71168, scored 7.3, is a second path traversal issue, this one abusable by a local low-privileged user. The FBI and CISA have been telling vendors since May 2024 to stop shipping path traversal bugs, calling them "unforgivable" since at least 2007. Dell shipped two in the same tool.
| CVE | Product | Severity | Fixed in |
|---|---|---|---|
| CVE-2026-86360 | Dell System Update | 9.6 Critical | 2.3.0.0 |
| CVE-2026-63697 | Dell System Update | 7.6 High | 2.3.0.0 |
| CVE-2026-71168 | Dell System Update | 7.3 High | 2.3.0.0 |
Is anyone actually being attacked?
Not with these specific bugs, as far as Dell has said. But the track record on Dell flaws is why this matters.
North Korea's Lazarus group spent years exploiting an older Dell driver bug, CVE-2021-21551, to plant a Windows rootkit, software that hides deep in the operating system. More recently, Mandiant and Google's Threat Intelligence Group identified suspected Chinese espionage actors who'd been quietly building backdoors on VMware ESXi servers since mid-2024 by abusing a hardcoded-credential bug, CVE-2026-22769, in Dell RecoverPoint for Virtual Machines. Days after that disclosure, CISA gave federal agencies three days to patch.
This is the pattern. Bugs in Dell's management and update plumbing get picked up by serious state-backed groups because that plumbing runs with root and sits inside the network. We've tracked the same dynamic in five path traversal cases over the past 90 days, the GitLab case in September being the clearest parallel. The postmortem writes itself: the tool meant to install patches was itself the way in.
Pull DSU to 2.3.0.0 this week.



