Dell released emergency patches to address four severe Dell Networking OS10 vulnerabilities today. These flaws allow attackers to steal user sessions, bypass access controls, and execute arbitrary code. Security researchers have confirmed no active exploitation or public proof-of-concept exploits for these issues.
Why This Threat Matters
Industry analysts estimate that thousands of enterprise data centers deploy Dell SmartFabric OS10 switches for core network routing. Therefore, critical flaws in these devices present major risks to corporate infrastructure. Attackers who exploit these Dell Networking OS10 vulnerabilities can hijack administrative sessions. Subsequently, they gain deep network access to intercept traffic or alter routing policies.
How the Attack Works
These vulnerabilities affect different access control and validation mechanisms. The most critical flaw, CVE-2026-63695, involves session fixation. According to the advisory, an unauthenticated attacker with remote access can exploit this bug to steal active sessions. Meanwhile, CVE-2026-63696 allows high-privileged users to download code without integrity checks. This action leads directly to unauthorized remote code execution. Additionally, CVE-2026-61418 involves incorrect authorization. This weakness permits low-privileged remote attackers to execute system commands. Finally, CVE-2026-61417 allows low-privileged users to cause a denial of service through improper access controls.
Affected Versions
These Dell Networking OS10 vulnerabilities impact multiple software releases. Specifically, they affect all Dell SmartFabric OS10 versions prior to 10.6.1.3.
Patch and Mitigation Steps
Network administrators must update their switch firmware immediately. Dell resolved these issues in version 10.6.1.3. You can download the remediated firmware from the official Dell support portal. Furthermore, read the official security update for Dell Networking OS10 to review deployment instructions. Currently, no workarounds exist for these vulnerabilities.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!