Ethical Hacking News
A critical security alert has been issued by Dell, urging its customers to patch a critical flaw in its System Update (DSU) tool. The vulnerability, tracked as CVE-2026-86360, is a path traversal issue that can allow attackers to execute code with root privileges on unpatched PowerEdge servers. Dell recommends that customers upgrade to version 2.3.0.0 or later to prevent exploitation of this critical vulnerability.
Dell has issued a critical security alert for a path traversal issue in its System Update (DSU) tool, CVE-2026-86360, which can allow attackers to execute code with root privileges. The vulnerability is considered critical because it can be leveraged by an unauthenticated attacker to execute arbitrary code with root privileges. Dell has not reported any active attacks exploiting these vulnerabilities so far, but recommends upgrading to version 2.3.0.0 or later to prevent exploitation. Four other vulnerabilities in System Update versions were also addressed, including improper certificate validation and path traversal vulnerabilities. Customers are advised to upgrade to version 2.3.0.0 or later as soon as possible to patch the vulnerabilities.
A critical security alert has been issued by Dell, urging its customers to patch a critical flaw in its System Update (DSU) tool. The vulnerability, tracked as CVE-2026-86360, is a path traversal issue that can allow attackers to execute code with root privileges on unpatched PowerEdge servers. This flaw could give attackers full control of vulnerable servers, posing a significant risk to the security of enterprise IT systems.
The vulnerability is considered critical because it can be leveraged by an unauthenticated attacker to execute arbitrary code with root privileges. Successful exploitation of this vulnerability may allow complete compromise of the vulnerable application and underlying operating system. Dell has not reported any active attacks exploiting these vulnerabilities so far, but the company recommends that customers upgrade to version 2.3.0.0 or later to prevent exploitation.
Beyond the critical CVE-2026-86360 flaw, Dell addressed four other vulnerabilities in System Update versions before 2.3.0.0. These vulnerabilities include CVE-2026-86361 and CVE-2026-86362, which could allow a low-privileged local attacker to gain higher privileges by exploiting incorrect permissions or access controls. Additionally, CVE-2026-63697 and CVE-2026-71168 are improper certificate validation and path traversal vulnerabilities, respectively, that could allow a highly privileged remote attacker to execute code.
The affected tool can expose multiple paths to privilege escalation or code execution, making it essential for customers to take prompt action to patch the vulnerabilities. Dell has provided guidance on how to apply the available security updates, and customers are advised to upgrade to version 2.3.0.0 or later as soon as possible.
The discovery of this critical vulnerability highlights the importance of regular security updates and patch management. It also underscores the need for customers to stay vigilant and proactive in protecting their systems from emerging threats. As the threat landscape continues to evolve, it is essential for organizations to prioritize their security posture and take prompt action to address vulnerabilities like CVE-2026-86360.
In conclusion, Dell's critical security alert serves as a reminder of the importance of staying up-to-date with the latest security patches and best practices. By taking prompt action to patch the CVE-2026-86360 flaw and other related vulnerabilities, customers can help prevent exploitation and protect their systems from potential threats.
Related Information:
https://www.ethicalhackingnews.com/articles/Dell-Urges-Customers-to-Patch-Critical-DSU-Flaw-That-Can-Give-Attackers-Root-Access-A-Critical-Security-Alert-ehn.shtml
https://securityaffairs.com/200458/security/dell-urges-customers-to-patch-critical-dsu-flaw-that-can-give-attackers-root-access.html
https://nvd.nist.gov/vuln/detail/CVE-2026-86360
https://www.cvedetails.com/cve/CVE-2026-86360/
https://nvd.nist.gov/vuln/detail/CVE-2026-86361
https://www.cvedetails.com/cve/CVE-2026-86361/
https://nvd.nist.gov/vuln/detail/CVE-2026-86362
https://www.cvedetails.com/cve/CVE-2026-86362/
https://nvd.nist.gov/vuln/detail/CVE-2026-63697
https://www.cvedetails.com/cve/CVE-2026-63697/
https://nvd.nist.gov/vuln/detail/CVE-2026-71168
https://www.cvedetails.com/cve/CVE-2026-71168/
Published: Tue Oct 6 02:36:11 2026 by llama3.2 3B Q4_K_M