Critical Dell System Update Flaw Could Lead To Full Server Takeover

Dell Servers
Dell Servers. Image: Dell.
Organizations utilizing Dell’s System Update (DSU) tools to manage their server infrastructure need to patch their software as quickly as possible. The company has pushed an update to address several major security issues, with the most worrying of the bunch severe enough to provide attackers deep access to a system without needing to be authenticated.

While all the vulnerabilities reported by the company are dangerous in some way, CVE-2026-86360, which is a path traversal vulnerability, is the headliner. According to Dell, “an unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access for [the] attacker.” Once an attacker has gained this access it can be leveraged to run arbitrary code alongside root privileges giving them significant control over the system.

Servers
Servers. Image: valaymtw via Pixabay.

Slightly lower on the totem pole are CVE-2026-86361, which is an Incorrect Permission Assignment for Critical Resource vulnerability, and CVE-2026-86362, an Improper Access Control vulnerability. Both require local access for an attacker to exploit them, and allow an attacker to gain elevation of privileges, even if they initially only have low privilege access to the system.

Then there’s CVE-2026-63697, an improper Certificate Validation vulnerability. An attacker with high privileges that has remote access to the system could potentially use it for remote execution.

Additionally, CVE-2026-71168 is another path traversal vulnerability that can be exploited by an attacker with low privileges, but local access. It can then be leveraged for remote execution as well.

While some of these vulnerabilities are going to be more difficult for an attacker to exploit because of the need for local access, IT administrators should still take them seriously. All of these vulnerabilities are present on DSU versions older than 2.3.0.0 and Dell is urging customers to “upgrade at the earliest opportunity.”
Alan Velasco

Alan Velasco

When Alan isn’t watching his favorite streamers on Twitch he’s writing about tech, gaming and cybersecurity.
 
Opinions and content posted by HotHardware contributors are their own.