Bleepingcomputer Critical Dell System Update Flaw Allows Root Access to Hackers
Article Content
- •CVE-2026-86360 allows root access via a path traversal vulnerability.
- •Dell recommends immediate upgrade to DSU version 2.3.0.0 or later.
- •No active exploitation reported, but history of state-backed attacks on Dell systems.
Dell has issued a warning about a critical vulnerability (CVE-2026-86360) in its System Update (DSU) tool that could allow unauthenticated attackers to execute code with root privileges on affected systems. This flaw, which stems from a path traversal weakness, affects versions prior to 2.3.0.0. Dell advises customers to upgrade to the latest version immediately to mitigate the risk. In addition to this critical flaw, Dell patched four other high-severity vulnerabilities on the same day, including two that allow remote code execution. Although there are no reports of at this time, the FBI and CISA have emphasized the importance of addressing such vulnerabilities, which have been labeled 'unforgivable' since 2007. The company has not confirmed any of these vulnerabilities, but there is a history of state-backed groups exploiting Dell vulnerabilities in the past.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Lazarus Hacking Group, Spawnant and Dell in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which versions of DSU are affected?
What should I do to protect my systems?
Is there any evidence of exploitation?
Continue Reading
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…
Critical Authentication Bypass in Rejetto HFS Exploited Within 24 Hours Anthropic's Mythos model identified a critical authentication bypass in Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500, allowing remote code execution. Discovered by Horizon3 researcher Zach Hanley, the flaw was revealed on September 27, 2026, and exploitation began within 24 hours, with attacks traced to…