CVE-2026-22769
KEVmoderateHard-coded credentials in Dell RecoverPoint for Virtual Machines allow root OS access
CISA: Dell RecoverPoint for Virtual Machines (RP4VMs) Use of Hard-coded Credentials Vulnerability
Dell RecoverPoint for Virtual Machines (RP4VMs) versions prior to 6.0.3.1 HF1 contain hard-coded credentials (CWE-798) for the appliance's underlying operating system. An unauthenticated remote attacker who knows the hard-coded credential can authenticate over the network with no user interaction and gain root-level access and persistence on the underlying OS — beyond just the RecoverPoint application — which is why the flaw scores a maximum CVSS of 10.0 with scope changed. Any organization running an affected RP4VMs release is exposed, with risk highest where appliance management interfaces are reachable from broader networks. The vulnerability is confirmed exploited in the wild: it was added to CISA's KEV catalog on 2026-02-18, and reporting indicates China-linked actors exploited it as a zero-day since at least 2024, prompting an emergency federal patch directive; related coverage ties the activity to the China-linked VerdantBamboo actor deploying BRICKSTORM-family backdoors on appliances.
What to do: Upgrade all RP4VMs appliances to 6.0.3.1 HF1 or apply Dell's published remediations immediately — federal agencies must patch per BOD 22-01 by the KEV deadline (reported as 'by Saturday'). Because exploitation has occurred since at least 2024, treat deployed appliances as potentially compromised: review the underlying OS for unexpected accounts, modified services, and root persistence, and restrict the appliance's management/replication network reachability until patched.
| Dell RecoverPoint for Virtual Machines (RP4VMs) | All versions prior to 6.0.3.1 HF1 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Dell RecoverPoint for Virtual Machines, versions prior to 6.0.3.1 HF1, contain a hardcoded credential vulnerability. This is considered critical as an unauthenticated remote attacker with knowledge of the hardcoded credential could potentially exploit this vulnerability leading to unauthorized access to the underlying operating system and root-level persistence. Dell recommends that customers upgrade or apply one of the remediations as soon as possible.
- Affected
- Dell RecoverPoint for Virtual Machines (RP4VMs)
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- dell
- Products
- recoverpoint for virtual machines
- Weakness
- CWE-798
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H