TL;DR
On October 1, Dell fixed five flaws in Dell System Update (DSU), led by a 9.6 path traversal bug. That flaw can let a remote, unauthenticated attacker run code as root. Version 2.3.0.0 fixes all five issues.
See a CVE's exploit risk spike before it becomes a headline.
Get EPSS spike alertsWhy It Matters
Admins use Dell System Update to push firmware and driver updates to Dell PowerEdge servers. Because the tool runs with high privileges, a flaw in it can hand over the whole machine. Dell rates the overall impact Critical.
The risk also grows with scale. Teams often run the same DSU build across many servers at once. As a result, one unpatched version can leave a whole data center exposed.
Dell has not reported exploitation in the wild. Likewise, no public proof-of-concept has surfaced so far.
How the Attacks Work
CVE-2026-86360: Path Traversal to Root
This is the most severe flaw. Dell says “an unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access.” The advisory adds that it “can be leveraged by an unauthenticated attacker to execute arbitrary code with root privileges.” Even so, the CVSS vector shows that a user must take some action for the attack to succeed.
CVE-2026-86361 and CVE-2026-86362: Local Privilege Escalation
Both bugs score 8.2. One stems from incorrect permissions on a critical resource. The other comes from weak access control. In each case, a low-privileged local user could raise their rights.
CVE-2026-63697: Weak Certificate Checks
This 7.6 flaw involves improper certificate validation. A high-privileged remote attacker could abuse it for remote execution. However, the attacker would already need high privileges, which lowers the risk.
CVE-2026-71168: Local Path Traversal
The last bug scores 7.3. A low-privileged local attacker could use a second path traversal flaw to reach remote execution.
Affected Versions
All Dell System Update versions prior to 2.3.0.0 are affected by all five flaws.
Patch and Mitigation Steps
Upgrade Now
Dell urges customers to “upgrade at the earliest opportunity.” Install DSU 2.3.0.0 or later, as the Dell DSA-2026-324 security advisory advises.
Harden in the Meantime
- Limit shell access on servers that run Dell System Update.
- Review local accounts and remove unneeded ones.
- Pull updates only from trusted Dell repositories.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!