New Dell System Update flaw lets hackers gain root privileges
Dell warns a critical System Update path-traversal flaw, CVE-2026-86360, lets unauthenticated attackers run code as root.
Dell warned that CVE-2026-86360, a critical path-traversal flaw in the Dell System Update CLI, lets an unauthenticated remote attacker access the filesystem and execute arbitrary code as root on unpatched systems. The same update fixes high-severity DSU bugs CVE-2026-63697 and CVE-2026-71168 for remote code execution and CVE-2026-86361 and CVE-2026-86362 for privilege escalation; customers should move to DSU 2.3.0.0 or later. Dell also urged immediate patching of maximum-severity Container Storage Modules flaws CVE-2026-63688 and CVE-2026-63692. Dell has not flagged these new issues as actively exploited.