Dell Patches Critical Root-Level Flaw in System Update Tool
Dell released version 2.3.0.0 of its System Update CLI tool to fix CVE-2026-86360, a path traversal flaw allowing unauthenticated remote code execution as root.
Dell has released a security advisory warning customers about a critical path traversal vulnerability in its Dell System Update (DSU) CLI deployment tool and issued version 2.3.0.0 to patch it, according to bleepingcomputer.com. The flaw is tracked as CVE-2026-86360 and allows unauthenticated remote attackers to execute code with root privileges.
Dell said successful exploitation could lead to complete compromise of the vulnerable application and the underlying operating system. The advisory did not flag any of the vulnerabilities as actively exploited.
Alongside the critical fix, Dell patched four high-severity DSU flaws. Two of them — CVE-2026-63697 and CVE-2026-71168 — allow remote code execution, while CVE-2026-86361 and CVE-2026-86362 enable privilege escalation.
Dell recommends upgrading Dell System Update to version 2.3.0.0 or later. The company also urged IT administrators to patch two maximum-severity Container Storage Modules vulnerabilities, tracked as CVE-2026-63688 and CVE-2026-63692.
Earlier Dell Security Incidents
In February, Mandiant and Google Threat Intelligence Group revealed that suspected Chinese cyber spies tracked as UNC6201 had exploited a hardcoded-credential vulnerability (CVE-2026-22769) in Dell RecoverPoint for Virtual Machines since at least mid-2024. Days after that report, CISA ordered federal agencies to patch vulnerable Dell systems within three days. Separately, the North Korean Lazarus hacking group exploited CVE-2021-21551, an insufficient access control flaw in the Dell dbutil driver, to deploy a Windows rootkit.
Quick answers
What is CVE-2026-86360?
It is a critical path traversal vulnerability in Dell System Update that allows unauthenticated remote attackers to execute code with root privileges, potentially compromising the application and underlying operating system.
Which Dell System Update version fixes the flaw?
Dell recommends upgrading to Dell System Update version 2.3.0.0 or later.
Are these Dell vulnerabilities being actively exploited?
Dell has not flagged any of the patched flaws as actively exploited.