Skip to content
Chinese Hackers Exploit Dell Zero-Day Flaw CVE-2026-22769 Since Mid-2024

Chinese Hackers Exploit Dell Zero-Day Flaw CVE-2026-22769 Since Mid-2024

First seen 17 Feb 2026, 21:10 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 16:10 UTC

A Chinese state-backed hacking group, UNC6201, has been exploiting a critical zero-day vulnerability in Dell RecoverPoint for Virtual Machines since at least mid-2024. The flaw, tracked as CVE-2026-22769, features a maximum severity rating due to hardcoded credentials, allowing unauthorized access to VMware virtual machine backups. This exploitation was revealed by Mandiant and the Google Threat Intelligence Group on February 17, 2026.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 213d ago How this analysis works

Timeline

2024-06-01
UNC6201 begins exploiting Dell RecoverPoint vulnerability
2026-02-17
CVE-2026-22769 published
2026-02-17
Mandiant and GTIG report on UNC6201's activities

More articles in this cluster (40)

Following this threat?

Track Silk Typhoon, Brickstorm and Dell in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed