Dell disclosed and researchers detailed CVE-2026-40639 (DSA-2026-197), a BIOS password storage weakness that allows administrator and user passwords to be recovered from SPI flash dumps in milliseconds on affected Dell client platforms. The flaw affects the SystemPwSmm SMM driver and stems from storing password records in the DVAR region with a reversible repeating 20-byte XOR scheme over a 32-byte field, while leaving the first password character unencrypted. For passwords of 12 characters or fewer, leaked key material is sufficient for deterministic recovery without brute force; researchers also reported that longer passwords are often recoverable because deleted DVAR records are not securely erased and key derivation is limited by device-specific values.
Confirmed vulnerable systems include the Wyse 5070 thin client and reported examples such as the Latitude E7250, Latitude 7490, and XPS 15 9560, although some newer Dell platforms were found to use stronger protections and were not affected. The attack requires physical access to read SPI flash or the ability to boot an attacker-controlled OS, but recovered BIOS credentials could let an attacker change settings tied to Secure Boot, boot order, and pre-boot DMA controls, potentially weakening some full-disk encryption assumptions. Dell validated the report after private disclosure, issued patches for some product lines, and said additional fixes were planned, though some confirmed vulnerable devices remained unpatched at publication time.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
One report stated Dell planned further patches for additional affected platforms by the end of July 2026. This followed the June 9 initial advisory and patch release, which did not yet cover all confirmed vulnerable devices.
MDSec and AmberWolf researchers publicly disclosed that Dell BIOS passwords could be deterministically recovered from SPI flash because of a reversible repeating-key XOR scheme and leaked key material in DVAR records. They reported confirmed impact on several Dell systems and said some vulnerable devices remained unpatched at publication time.
Dell published advisory DSA-2026-197 for CVE-2026-40639 and issued patches for some affected platform lines. Multiple reports note that several confirmed vulnerable systems were still not covered by the initial fixes.
The CVE-2026-40639 BIOS password recovery issue was privately disclosed to Dell, which later validated the report. The flaw affects Dell's storage of BIOS administrator and user passwords in SPI flash.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
reddit.com
Open sourcecybersecuritynews.com
Open sourcecryptika.com
Open sourcemdsec.co.uk
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.