Particle.news

Critical Path Traversal in Dell System Update Lets Remote Attackers Gain Root Access

The flaw lets unauthenticated remote attackers execute code as root on PowerEdge servers, prompting urgent remediation orders from U.S. cybersecurity agencies.

Overview

  • Dell disclosed a critical path traversal bug tracked as CVE-2026-86360 in its System Update (DSU) tool and released DSU 2.3.0.0 with a fix.
  • The vulnerability has a reported CVSS score of 9.6 and can let an attacker with remote access write to the filesystem and run arbitrary code as root.
  • Dell also patched four other high-severity DSU flaws that include two remote code execution issues (CVE-2026-63697 and CVE-2026-71168) and two privilege-escalation bugs (CVE-2026-86361 and CVE-2026-86362).
  • CISA ordered federal agencies to remediate affected Dell systems within three days and Dell is urging all customers to upgrade to DSU 2.3.0.0 or later as soon as possible.
  • Because DSU is used to push BIOS, firmware, and software updates to PowerEdge servers, successful exploitation could give attackers full control of enterprise servers and echoes past nation-state abuses of Dell flaws, increasing the urgency of rapid patching.