Critical Dell System Update Flaw Could Lead To Full Server Takeover
While all the vulnerabilities reported by the company are dangerous in some way, CVE-2026-86360, which is a path traversal vulnerability, is the headliner. According to Dell, “an unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access for [the] attacker.” Once an attacker has gained this access it can be leveraged to run arbitrary code alongside root privileges giving them significant control over the system.

Slightly lower on the totem pole are CVE-2026-86361, which is an Incorrect Permission Assignment for Critical Resource vulnerability, and CVE-2026-86362, an Improper Access Control vulnerability. Both require local access for an attacker to exploit them, and allow an attacker to gain elevation of privileges, even if they initially only have low privilege access to the system.
Then there’s CVE-2026-63697, an improper Certificate Validation vulnerability. An attacker with high privileges that has remote access to the system could potentially use it for remote execution.
Additionally, CVE-2026-71168 is another path traversal vulnerability that can be exploited by an attacker with low privileges, but local access. It can then be leveraged for remote execution as well.
While some of these vulnerabilities are going to be more difficult for an attacker to exploit because of the need for local access, IT administrators should still take them seriously. All of these vulnerabilities are present on DSU versions older than 2.3.0.0 and Dell is urging customers to “upgrade at the earliest opportunity.”