Dell urged customers to patch CVE-2026-86360, a critical path traversal vulnerability in Dell System Update (DSU) versions before 2.3.0.0. Rated 9.6 CVSS, the flaw could allow an unauthenticated remote attacker to access the filesystem and execute arbitrary code with root privileges, potentially compromising the application and underlying operating system completely, including affected PowerEdge servers.
Dell recommends upgrading to DSU 2.3.0.0 or later at the earliest opportunity. The release also fixes four high-severity vulnerabilities involving privilege escalation, improper certificate validation, and path traversal, with potential consequences including code execution. Dell’s advisory does not state whether any of the five vulnerabilities have been exploited in the wild; organizations should prioritize identifying affected installations and deploying the update.

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
Dell urged IT administrators to promptly patch CVE-2026-63688 and CVE-2026-63692 in Container Storage Modules, both described as maximum-severity vulnerabilities. Dell had not marked either vulnerability as actively exploited at the time of the report.
Dell fixed the five System Update vulnerabilities in version 2.3.0.0 and urged customers to upgrade to that version or later at the earliest opportunity.
Dell disclosed five vulnerabilities affecting System Update versions before 2.3.0.0, including CVE-2026-86360, a critical path traversal flaw rated CVSS 9.6 that could let an unauthenticated remote attacker execute arbitrary code with root privileges. The other four vulnerabilities could enable privilege escalation or code execution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
5 references tracked. Mallory keeps watching after this page renders.
acn.gov.it
Open sourcecybersecuritynews.com
Open sourcehelpnetsecurity.com
Open sourcemkd-cirt.mk
Open sourcesecurityaffairs.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.