Skip to content
Critical Dell System Update Flaw Allows Root Access to Hackers

Critical Dell System Update Flaw Allows Root Access to Hackers

First seen 5 Oct 2026, 17:05 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 5, 2026 at 17:06 UTC
  • •CVE-2026-86360 allows root access via a path traversal vulnerability.
  • •Dell recommends immediate upgrade to DSU version 2.3.0.0 or later.
  • •No active exploitation reported, but history of state-backed attacks on Dell systems.

Dell has issued a warning about a critical vulnerability (CVE-2026-86360) in its System Update (DSU) tool that could allow unauthenticated attackers to execute code with root privileges on affected systems. This flaw, which stems from a path traversal weakness, affects versions prior to 2.3.0.0. Dell advises customers to upgrade to the latest version immediately to mitigate the risk. In addition to this critical flaw, Dell patched four other high-severity vulnerabilities on the same day, including two that allow remote code execution. Although there are no reports of at this time, the FBI and CISA have emphasized the importance of addressing such vulnerabilities, which have been labeled 'unforgivable' since 2007. The company has not confirmed any of these vulnerabilities, but there is a history of state-backed groups exploiting Dell vulnerabilities in the past.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2021-05-04
CVE-2021-21551 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-02-17
CVE-2026-22769 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-10-05
Dell warns of critical DSU vulnerability
Dell disclosed a critical path traversal vulnerability (CVE-2026-86360) in its System Update tool, urging immediate patching.
BleepingComputer
2026-10-05
Dell releases security patches
Dell patched multiple vulnerabilities in DSU, including CVE-2026-86360, CVE-2026-63697, and others, advising customers to upgrade.
Dell

More articles in this cluster (2)

Following this threat?

Track Lazarus Hacking Group, Spawnant and Dell in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which versions of DSU are affected?
Dell System Update versions prior to 2.3.0.0 are affected by the vulnerabilities.
What should I do to protect my systems?
Upgrade to Dell System Update version 2.3.0.0 or later as soon as possible to mitigate the vulnerabilities.
Is there any evidence of exploitation?
Currently, there are no confirmed reports of active exploitation of these vulnerabilities.