Protect.Computer
NEWS

Dell System Update Critical Flaw Allows Root Code Execution

· 1 min read · Device safety
Dell System Update Critical Flaw Allows Root Code Execution

Dell has warned customers to patch a critical vulnerability in the Dell System Update (DSU) command-line tool as soon as possible. DSU is what enterprise IT administrators use to deploy BIOS, firmware and software updates to PowerEdge servers running Linux and Windows. The flaw, CVE-2026-86360, is a path-traversal weakness that Dell says an unauthenticated attacker with remote access could exploit to execute arbitrary code with root privileges, potentially compromising the application and the underlying operating system.

Dell fixed four more high-severity DSU flaws in the same Thursday advisory: two that remote attackers can exploit for remote code execution (CVE-2026-63697 and CVE-2026-71168) and two privilege-escalation bugs (CVE-2026-86361 and CVE-2026-86362). Dell has not flagged any of them as actively exploited, but BleepingComputer notes that state-backed groups have abused other Dell vulnerabilities in recent years. Dell also urged customers to patch two maximum-severity Container Storage Modules flaws, CVE-2026-63688 and CVE-2026-63692.

How to check if you’re affected

Affected products are installations of Dell System Update (DSU) on Linux or Windows. Affected versions are anything older than 2.3.0.0, the release Dell says fixes all five flaws. Check the DSU version installed on each PowerEdge management host or jump box and upgrade to 2.3.0.0 or later. Dell’s advisory is DSA-2026-324.

Sources

Related reading