Critical Dell System Update Tool Vulnerability Allows Attackers to Execute Code as Root User
Dell patched five System Update flaws, including CVSS 9.6 path traversal that can execute code as root.
Dell advisory DSA-2026-324, published October 1, 2026, covers five flaws in Dell System Update before version 2.3.0.0. CVE-2026-86360 (CVSS 9.6) is a path traversal bug that could let a remote unauthenticated attacker access the filesystem and run code as root, though the CVSS vector requires user interaction. CVE-2026-86361 and CVE-2026-86362 (both 8.2) are local privilege issues; CVE-2026-63697 (7.6) is improper certificate validation and CVE-2026-71168 (7.3) is another path traversal. Dell says 2.3.0.0 or later fixes all five and has not reported active exploitation.