"An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access for [an] attacker," Dell said.
CVE-2026-86360: a path traversal that can yield root
Dell on Thursday warned customers that a critical flaw in its System Update (DSU) command-line interface (CLI) deployment tool — tracked as CVE-2026-86360 — can be exploited to execute code with root privileges on unpatched systems. The company described the vulnerability as a path traversal weakness that, if exploited by an unauthenticated attacker with remote access, could allow arbitrary code execution with full control of the underlying operating system.
Dell summarized the risk bluntly: "This vulnerability is considered critical because it can be leveraged by an unauthenticated attacker to execute arbitrary code with root privileges. Successful exploitation may allow complete compromise of the vulnerable application and underlying operating system."
Dell System Update (DSU) and the 2.3.0.0 patch
DSU is a deployment tool used by enterprise IT administrators to push BIOS, firmware, and software updates onto Linux and Windows systems running on PowerEdge enterprise server infrastructure. Dell recommended that customers update DSU to version 2.3.0.0 or later, which the company said patches CVE-2026-86360.
While Dell has not flagged CVE-2026-86360 as being actively exploited in the wild, the vendor's advisory stressed the criticality of the flaw and urged administrators to upgrade "at the earliest opportunity."

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildAdditional patches: other DSU flaws and Container Storage Modules
Alongside CVE-2026-86360, Dell patched four other high-severity DSU issues the same day. Two of those could allow remote code execution (CVE-2026-63697 and CVE-2026-71168) and two could be abused for privilege escalation (CVE-2026-86361 and CVE-2026-86362).
On the same Thursday Dell also warned administrators to patch two maximum-severity Container Storage Modules (CSM) vulnerabilities, tracked as CVE-2026-63688 and CVE-2026-63692, "as soon as possible."
Past Dell vulnerabilities and state-backed exploitation
The advisory arrives against a backdrop of documented abuses of Dell flaws by state-backed groups in recent years. The report cites a North Korean operation in which the Lazarus group deployed a Windows rootkit via an insufficient access control vulnerability in the Dell dbutil driver (CVE-2021-21551).
More recently, Mandiant and the Google Threat Intelligence Group revealed in February that suspected Chinese cyber spies tracked as UNC6201 had been exploiting a hardcoded-credential vulnerability (CVE-2026-22769) in Dell RecoverPoint for Virtual Machines since at least mid-2024 to create hidden network interfaces on VMware ESXi servers and deploy malware payloads. Those researchers also reported overlaps between UNC6201 and the Silk Typhoon Chinese cyberespionage group, which had been linked to targeted attacks using custom Zipline and Spawnant malware in Ivanti zero-day incidents.
Following those February findings, CISA ordered federal agencies to patch vulnerable Dell systems on their networks within three days.
What this means for enterprise IT administrators, federal agencies, and adversaries
- Enterprise IT administrators: Dell's recommendation to upgrade DSU to 2.3.0.0 or later is the concrete remediation path. Administrators who use DSU to roll out BIOS, firmware, and software updates on PowerEdge systems must prioritize the update to close a vector that can lead to complete system compromise.
- Federal agencies and regulators: Given CISA's earlier near-term patching directive following February disclosures, agencies will weigh the vendor advisory alongside existing patching orders and incident response plans, particularly because the U.S. Cybersecurity and Infrastructure Security Agency and the FBI have urged software companies since May 2024 to remove path traversal weaknesses before shipping.
- Adversaries and threat actors: Although Dell has not reported active exploitation of CVE-2026-86360, past campaigns exploiting Dell vulnerabilities underline the attractiveness of such flaws to state-backed groups and others seeking persistent, high-privilege access to enterprise servers.
Dell's advisory and the accompanying set of fixes close immediate technical holes. The record of prior exploitation, the public guidance from federal agencies to eliminate path traversal defects, and CISA's rapid patching directives together frame the present moment as one that tests how quickly large enterprises and government networks can apply vendor fixes. The open question the facts leave is straightforward: will patch deployment keep pace with the window of exposure for organizations that rely on DSU and related Dell components?




