Vulnerabilities
4 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-81467 | Unauthenticated OS Command Injection RCE in Dell ThinOS 10 Dell ThinOS 10, the operating system for Dell Wyse thin clients, contains an OS command injection flaw (CWE-78) in versions prior to 2605_10.2616, where insufficiently sanitized input passed to an operating system command can be abused by an attacker. An unauthenticated attacker with network access to an affected device can send crafted input to the vulnerable interface and achieve arbitrary command execution on the thin client. Successful exploitation carries maximum impact (CVSS 3.1 9.8, scored with high confidentiality, integrity, and availability impact), potentially giving attackers a foothold in enterprise VDI environments. Any organization running Dell Wyse thin clients on ThinOS 10 below 2605_10.2616 is affected, particularly deployments where management or remote-access services on the devices are reachable from untrusted networks. As of now there is no known exploitation, no public proof-of-concept, and the issue is not listed in CISA's Known Exploited Vulnerabilities catalog. Do: Upgrade affected thin clients to ThinOS 10 version 2605_10.2616 or later. Until patched, restrict network access to thin client management and remote-access services so they are not reachable by unauthenticated or untrusted users. Inventory Wyse deployments for ThinOS 10 versions below 2605_10.2616 and monitor for anomalous inbound connections or unexpected processes on those devices. | 9.8 group max | — |
| largeon the order of 100,000–1,000,000 deployed Wyse thin clients running ThinOS 10 (internet-exposed subset unknown) |