Overview
- Dell disclosed a critical path traversal bug tracked as CVE-2026-86360 in its System Update (DSU) tool and released DSU 2.3.0.0 with a fix.
- The vulnerability has a reported CVSS score of 9.6 and can let an attacker with remote access write to the filesystem and run arbitrary code as root.
- Dell also patched four other high-severity DSU flaws that include two remote code execution issues (CVE-2026-63697 and CVE-2026-71168) and two privilege-escalation bugs (CVE-2026-86361 and CVE-2026-86362).
- CISA ordered federal agencies to remediate affected Dell systems within three days and Dell is urging all customers to upgrade to DSU 2.3.0.0 or later as soon as possible.
- Because DSU is used to push BIOS, firmware, and software updates to PowerEdge servers, successful exploitation could give attackers full control of enterprise servers and echoes past nation-state abuses of Dell flaws, increasing the urgency of rapid patching.