Cyber Security News

Critical Dell System Update Tool Vulnerability Allows Attackers to Execute Code as Root User

Dell has released security updates for five vulnerabilities in Dell System Update (DSU), including a critical flaw that could let an unauthenticated remote attacker execute code with root privileges. The issues affect versions before 2.3.0.0, and Dell urges customers to upgrade at the earliest opportunity.

The company published security advisory DSA-2026-324 on October 1, 2026. DSU is a command-line tool that helps administrators deploy BIOS, firmware, and software updates across Dell PowerEdge servers running Linux and Windows, making its security important for enterprise server management.

Critical Path Traversal Vulnerability

The most serious issue, CVE-2026-86360, carries a CVSS score of 9.6. Dell identifies it as a path traversal vulnerability, meaning the tool fails to keep file access within an intended directory. An attacker with remote access could exploit the weakness without first signing in to the affected system.

Dell warns that exploitation could provide filesystem access and allow arbitrary code execution with root privileges. Successful attacks could completely compromise both DSU and the underlying operating system. However, the published CVSS vector lists user interaction as required, an important detail that distinguishes unauthenticated access from an attack requiring no user involvement.

Dell credits researcher Ori Gabriel with reporting this critical flaw and the separate certificate validation issue. The advisory does not describe the exact user action required, vulnerable file paths, or a complete attack sequence. These limits matter: the warning establishes serious risk, but does not provide enough detail to reconstruct an exploit.

Four Additional Security Flaws

Two further vulnerabilities could allow local users with limited permissions to gain higher privileges. CVE-2026-86361 involves incorrect permissions assigned to a critical resource, while CVE-2026-86362 stems from improper access control. Both carry CVSS scores of 8.2 and require local access, unlike the critical remote path traversal flaw.

CVE-2026-63697, rated 7.6, involves improper certificate validation. Dell says a remote attacker who already holds high privileges could exploit it to achieve remote execution. CVE-2026-71168, rated 7.3, is another path traversal flaw. Its stated prerequisite is local access with low privileges, although Dell describes its potential outcome as remote execution.

Dell lists DSU version 2.3.0.0 or later as the fix for all five vulnerabilities. Administrators should identify installations below that version and obtain the corrected release through the official Dell download linked in the advisory. Installing an earlier DSU release does not meet Dell’s stated remediation requirement.

The disclosure follows separate critical Dell Container Storage vulnerabilities covered by Cyber Security News, highlighting another update priority for Dell environments. Those flaws affect a different product and need separate remediation. Dell had not flagged the DSU flaws as actively exploited in reporting published October 5, but customers should not delay patching.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup into your SOC

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Midnight Blizzard Abuses Hotel Wi-Fi Captive Portals to Deliver Malware and Steal Credentials

Travelers connecting to hotel Wi-Fi may now face more than an unreliable internet signal. A…

2 hours ago

Meta and Microsoft are Actively Cutting Employee Use of Claude AI

Meta and Microsoft are reducing employee use of Anthropic’s Claude AI while pushing their own…

3 hours ago

ClingSTUN Backdoor Exploits Multiple IoT Vulnerabilities to Gain Persistent Remote Access

ClingSTUN is a Linux backdoor that exploits vulnerable internet-connected devices to give attackers lasting remote…

4 hours ago

FBI Cuts Accenture Contractor Over Unpatched PeopleSoft Flaw Exposing Thousands

The FBI removed an Accenture contractor on October 5, 2026, after a missed security patch…

4 hours ago

Google Adds 6 Advanced Protection Features to Android 17 Against Sophisticated Attacks

Google has detailed six Advanced Protection enhancements for Android 17, targeting sophisticated attacks, scams and…

4 hours ago

Atlassian Patches Critical Vulnerabilities in Jira, Confluence, Bitbucket, and Five More Products

Atlassian has disclosed a critical arbitrary file access vulnerability affecting eight products, including Jira, Confluence,…

5 hours ago