Skip to content
Critical Vulnerabilities in Dell Wyse Management Suite Enable Remote Code Execution

Critical Vulnerabilities in Dell Wyse Management Suite Enable Remote Code Execution

First seen 29 Jun 2026, 19:04 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •June 30, 2026 at 18:43 UTC
  • •CVE-2026-41120 allows low-privileged attackers to execute remote code with a CVSS score of 9.8.
  • •CVE-2026-49506 is a path traversal vulnerability requiring high privileges for exploitation.
  • •Dell has released a patch for WMS, urging immediate upgrades to mitigate risks.

Dell Technologies has disclosed critical vulnerabilities in its Wyse Management Suite (WMS) that allow remote attackers to execute arbitrary code. The vulnerabilities, identified as CVE-2026-41120 and CVE-2026-49506, affect WMS versions prior to 5.5 HF1. CVE-2026-41120, with a CVSS score of 9.8, enables low-privileged attackers to exploit the flaw without user interaction. CVE-2026-49506 is a path traversal vulnerability requiring high privileges for exploitation. Organizations using WMS are at risk of significant impacts on confidentiality, integrity, and availability. Dell has released a patch for these vulnerabilities, urging immediate upgrades. Security teams are advised to enhance monitoring and review access controls to mitigate risks. The vulnerabilities were disclosed by security researcher Tien Phan.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 92d ago How this analysis works

Timeline

2026-03-20
CVE-2026-33017 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-08
Patch released for WMS
Dell released version 5.5 HF1 to address the critical vulnerabilities in WMS.
Gbhackers
2026-06-25
CVE-2026-41120 published
A critical vulnerability allowing low-privileged remote code execution was disclosed.
Gbhackers
2026-06-25
CVE-2026-49506 published
A path traversal vulnerability was disclosed, enabling high-privileged remote code execution.
Gbhackers

More articles in this cluster (6)

Following this threat?

Track Stockstay, Dell and CVE-2026-33017 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed