Critical Dell System Update flaw hands attackers root on PowerEdge servers
Dell patched five flaws in its System Update deployment tool, led by a CVSS 9.6 path traversal bug that can let a remote, unauthenticated attacker run code as root. Version 2.3.0.0 fixes all of them.
At a glance
- CVE-2026-86360 (CVSS 9.6) is a path traversal flaw in Dell System Update that can lead to arbitrary code execution with root privileges
- Four additional flaws were fixed at the same time, two of them local privilege escalation bugs rated 8.2
- All DSU versions before 2.3.0.0 are affected; DSU is widely used to push firmware and driver updates to PowerEdge servers
- Dell has not reported exploitation in the wild and no public proof-of-concept has surfaced
Dell has patched a critical vulnerability in Dell System Update (DSU), the command-line tool administrators use to push firmware, BIOS and driver updates to Dell hardware, that can give a remote and unauthenticated attacker root-level code execution on the underlying server. BleepingComputer reports that the flaw, tracked as CVE-2026-86360, was fixed alongside four other issues and that Dell is urging customers to upgrade immediately.
What happened
According to SecurityOnline, Dell published the advisory on October 1, 2026 and addressed five vulnerabilities in a single release. The most severe is CVE-2026-86360, a path traversal weakness that SecurityOnline reports carries a CVSS score of 9.6. Dell's own advisory, as quoted by BleepingComputer, describes the impact as enabling "complete compromise of the vulnerable application and underlying operating system."
SecurityOnline notes Dell's description of the bug: an "unauthenticated attacker with remote access could potentially exploit this vulnerability" to reach the filesystem and execute arbitrary code as root. The same report adds that the attack requires some user interaction to succeed, which limits — but does not eliminate — the exposure.
Technical details
The five issues fixed in this release, with the scores reported by SecurityOnline, are:
CVE-2026-86360(CVSS 9.6) — path traversal leading to filesystem access and root code executionCVE-2026-86361(CVSS 8.2) — incorrect permissions allowing a low-privileged user to escalateCVE-2026-86362(CVSS 8.2) — weak access control enabling privilege elevationCVE-2026-63697(CVSS 7.6) — improper certificate validation exploitable by a high-privileged attackerCVE-2026-71168(CVSS 7.3) — local path traversal leading to code execution
BleepingComputer categorises CVE-2026-63697 and CVE-2026-71168 as remote code execution issues and CVE-2026-86361 and CVE-2026-86362 as privilege escalation issues.
All DSU versions before 2.3.0.0 are affected, and 2.3.0.0 or later fixes all five, according to SecurityOnline.
Who is affected
The risk here comes less from the bug class than from where the tool sits. SecurityOnline points out that administrators use DSU to deliver firmware and driver updates to Dell PowerEdge servers and that the utility runs with high privileges by design — so a flaw inside it can hand over the entire machine rather than a single application. In fleets where DSU is scripted into patch automation across hundreds of servers, a single compromised update path has outsized reach.
Neither report indicates that the flaws are being exploited. SecurityOnline states that Dell has not reported exploitation in the wild and that no public proof-of-concept has surfaced so far, and BleepingComputer similarly notes that no active exploitation was flagged as of the announcement date.
BleepingComputer also places the bug in a broader context, recalling that the FBI and CISA have described path traversal vulnerabilities as "unforgivable" since 2007 and have repeatedly pressed vendors to eliminate them before shipping.
What to do
Upgrade Dell System Update to 2.3.0.0 or later on every host where it is installed, including jump hosts and management servers that only run it occasionally. SecurityOnline reports that Dell additionally recommends restricting shell access on affected servers, removing unnecessary local accounts, and downloading updates only from official Dell repositories — measures that reduce the value of both the remote path traversal and the two local escalation bugs. Teams that have wrapped DSU in automation should confirm the updated binary is what their scripts actually invoke.
Related CVEs
Sources
- New Dell System Update flaw lets hackers gain root privileges — BleepingComputer
- Dell System Update CVE-2026-86360 — SecurityOnline
This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.



