Warning: Critical vulnerability in Dell Wyse, remote code execution for remote, low privileged at...
These vulnerabilities affect the Dell Wyse Management Suite. They have a high impact on confidentiality, integrity and availability by allowing a remote attacker to execute code.
Dell gives little information these vulnerabilities and some of the information provided is seemingly contradictive.
CVE-2026-41120 is a vulnerability concerning acceptance of untrusted data where a low-privileged attacker can remotely execute code. The CVSS vector string shows no privileges being required. In the case of a software like this, low privileges might mean a lot of devices.
CVE-2026-49506 is a path traversal vulnerability that allows a high privileged attacker to achieve remote code execution.
The Centre for Cybersecurity Belgium strongly recommends installing updates for vulnerable devices with the highest priority, after thorough testing.
The CCB recommends organizations upscale monitoring and detection capabilities to identify any related suspicious activity, ensuring a swift response in case of an intrusion.
In case of an intrusion, you can report an incident via: .
While patching appliances or software to the newest version may provide safety from future exploitation, it does not remediate historic compromise.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
