ZeroHour

CVE-2026-22769

KEVmoderate

Hard-coded credentials in Dell RecoverPoint for Virtual Machines allow root OS access

CISA: Dell RecoverPoint for Virtual Machines (RP4VMs) Use of Hard-coded Credentials Vulnerability

CVSS 3.1
10.0 critical
EPSS
13%p96
Published
()
KEV added
AI analysis

Dell RecoverPoint for Virtual Machines (RP4VMs) versions prior to 6.0.3.1 HF1 contain hard-coded credentials (CWE-798) for the appliance's underlying operating system. An unauthenticated remote attacker who knows the hard-coded credential can authenticate over the network with no user interaction and gain root-level access and persistence on the underlying OS — beyond just the RecoverPoint application — which is why the flaw scores a maximum CVSS of 10.0 with scope changed. Any organization running an affected RP4VMs release is exposed, with risk highest where appliance management interfaces are reachable from broader networks. The vulnerability is confirmed exploited in the wild: it was added to CISA's KEV catalog on 2026-02-18, and reporting indicates China-linked actors exploited it as a zero-day since at least 2024, prompting an emergency federal patch directive; related coverage ties the activity to the China-linked VerdantBamboo actor deploying BRICKSTORM-family backdoors on appliances.

What to do: Upgrade all RP4VMs appliances to 6.0.3.1 HF1 or apply Dell's published remediations immediately — federal agencies must patch per BOD 22-01 by the KEV deadline (reported as 'by Saturday'). Because exploitation has occurred since at least 2024, treat deployed appliances as potentially compromised: review the underlying OS for unexpected accounts, modified services, and root persistence, and restrict the appliance's management/replication network reachability until patched.

Affected
Dell RecoverPoint for Virtual Machines (RP4VMs)All versions prior to 6.0.3.1 HF1
Estimated exposure
moderate≈ tens of thousands of appliances worldwide (estimated from deployment patterns; internet-exposed count unknown) — RP4VMs is an enterprise-only virtual appliance used for VM replication, typically deployed as a handful of instances per datacenter, so a global footprint on the order of 10,000–100,000 appliances is plausible; no public install-base…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Dell RecoverPoint for Virtual Machines, versions prior to 6.0.3.1 HF1, contain a hardcoded credential vulnerability. This is considered critical as an unauthenticated remote attacker with knowledge of the hardcoded credential could potentially exploit this vulnerability leading to unauthorized access to the underlying operating system and root-level persistence. Dell recommends that customers upgrade or apply one of the remediations as soon as possible.

CISA Known Exploited Vulnerability
Affected
Dell RecoverPoint for Virtual Machines (RP4VMs)
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
dell
Products
recoverpoint for virtual machines
Weakness
CWE-798
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

In the news