Critical Dell System Update flaw hands attackers root on PowerEdge servers

Dell patched five flaws in its System Update deployment tool, led by a CVSS 9.6 path traversal bug that can let a remote, unauthenticated attacker run code as root. Version 2.3.0.0 fixes all of them.

Critical Dell System Update flaw hands attackers root on PowerEdge servers

At a glance

  • CVE-2026-86360 (CVSS 9.6) is a path traversal flaw in Dell System Update that can lead to arbitrary code execution with root privileges
  • Four additional flaws were fixed at the same time, two of them local privilege escalation bugs rated 8.2
  • All DSU versions before 2.3.0.0 are affected; DSU is widely used to push firmware and driver updates to PowerEdge servers
  • Dell has not reported exploitation in the wild and no public proof-of-concept has surfaced

Dell has patched a critical vulnerability in Dell System Update (DSU), the command-line tool administrators use to push firmware, BIOS and driver updates to Dell hardware, that can give a remote and unauthenticated attacker root-level code execution on the underlying server. BleepingComputer reports that the flaw, tracked as CVE-2026-86360, was fixed alongside four other issues and that Dell is urging customers to upgrade immediately.

What happened

According to SecurityOnline, Dell published the advisory on October 1, 2026 and addressed five vulnerabilities in a single release. The most severe is CVE-2026-86360, a path traversal weakness that SecurityOnline reports carries a CVSS score of 9.6. Dell's own advisory, as quoted by BleepingComputer, describes the impact as enabling "complete compromise of the vulnerable application and underlying operating system."

SecurityOnline notes Dell's description of the bug: an "unauthenticated attacker with remote access could potentially exploit this vulnerability" to reach the filesystem and execute arbitrary code as root. The same report adds that the attack requires some user interaction to succeed, which limits — but does not eliminate — the exposure.

Technical details

The five issues fixed in this release, with the scores reported by SecurityOnline, are:

  • CVE-2026-86360 (CVSS 9.6) — path traversal leading to filesystem access and root code execution
  • CVE-2026-86361 (CVSS 8.2) — incorrect permissions allowing a low-privileged user to escalate
  • CVE-2026-86362 (CVSS 8.2) — weak access control enabling privilege elevation
  • CVE-2026-63697 (CVSS 7.6) — improper certificate validation exploitable by a high-privileged attacker
  • CVE-2026-71168 (CVSS 7.3) — local path traversal leading to code execution

BleepingComputer categorises CVE-2026-63697 and CVE-2026-71168 as remote code execution issues and CVE-2026-86361 and CVE-2026-86362 as privilege escalation issues.

All DSU versions before 2.3.0.0 are affected, and 2.3.0.0 or later fixes all five, according to SecurityOnline.

Who is affected

The risk here comes less from the bug class than from where the tool sits. SecurityOnline points out that administrators use DSU to deliver firmware and driver updates to Dell PowerEdge servers and that the utility runs with high privileges by design — so a flaw inside it can hand over the entire machine rather than a single application. In fleets where DSU is scripted into patch automation across hundreds of servers, a single compromised update path has outsized reach.

Neither report indicates that the flaws are being exploited. SecurityOnline states that Dell has not reported exploitation in the wild and that no public proof-of-concept has surfaced so far, and BleepingComputer similarly notes that no active exploitation was flagged as of the announcement date.

BleepingComputer also places the bug in a broader context, recalling that the FBI and CISA have described path traversal vulnerabilities as "unforgivable" since 2007 and have repeatedly pressed vendors to eliminate them before shipping.

What to do

Upgrade Dell System Update to 2.3.0.0 or later on every host where it is installed, including jump hosts and management servers that only run it occasionally. SecurityOnline reports that Dell additionally recommends restricting shell access on affected servers, removing unnecessary local accounts, and downloading updates only from official Dell repositories — measures that reduce the value of both the remote path traversal and the two local escalation bugs. Teams that have wrapped DSU in automation should confirm the updated binary is what their scripts actually invoke.

Related CVEs

Sources

This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.