Dell Urges Customers to Patch Critical DSU Flaw That Can Give Attackers Root Access
Dell urges patching CVE-2026-86360, a CVSS 9.6 path traversal in System Update that can give unauthenticated attackers root on PowerEdge servers.
Dell warned that System Update versions before 2.3.0.0 contain CVE-2026-86360, a path-traversal vulnerability scored CVSS 9.6. An unauthenticated remote attacker could gain filesystem access and execute arbitrary code as root on affected PowerEdge servers. Dell also fixed CVE-2026-86361 and CVE-2026-86362 (both 8.2), CVE-2026-63697 (7.6), and CVE-2026-71168 (7.3), covering local privilege escalation, improper certificate validation, and another path traversal. Customers should upgrade to 2.3.0.0 or later; Dell has not reported active attacks.
- CVE-2026-86360 is a CVSS 9.6 path traversal enabling unauthenticated remote root code execution
- Flaw affects Dell System Update versions before 2.3.0.0 on PowerEdge systems
- Four more flaws, scored 7.3 to 8.2, were fixed in the same release
- Dell has not reported active exploitation
Vulnerabilities mentionedAll →
- CVE-2026-863609.6—Unauthenticated Path Traversal to Root Code Execution in Dell System Updatepublished · Dell System Update (DSU)+4 related
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
CVE-2026-86360+4 related CVEs | Unauthenticated Path Traversal to Root Code Execution in Dell System Update |
Full article333 words · extracted from securityaffairs.com · click to collapse

Dell warns that a critical DSU flaw lets attackers run code as root. Customers should patch affected PowerEdge systems as soon as possible.
Dell urged customers to patch a critical flaw, tracked as CVE-2026-86360 (CVSS score of 9.6), in its System Update (DSU) tool. The vulnerability is a path traversal issue that can let attackers execute code with root privileges on unpatched PowerEdge servers. This flaw could give attackers full control of vulnerable servers. DSU is used by enterprise IT teams to deploy BIOS, firmware and software updates on Linux and Windows systems. The vendor recommends applying the available security updates as soon as possible to prevent exploitation.
“Dell System Update, versions prior to 2.3.0.0, contains an Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access for attacker.” reads the advisory. “This vulnerability is considered critical because it can be leveraged by an unauthenticated attacker to execute arbitrary code with root privileges. Successful exploitation may allow complete compromise of the vulnerable application and underlying operating system. Dell recommends customers upgrade at the earliest opportunity.”
Beyond the critical CVE-2026-86360 flaw, Dell addressed four other vulnerabilities in System Update versions before 2.3.0.0. CVE-2026-86361 and CVE-2026-86362, both rated 8.2, could allow a low-privileged local attacker to gain higher privileges by exploiting incorrect permissions or access controls. CVE-2026-63697 (CVSS score of 7.6) is an improper certificate validation flaw that could allow a highly privileged remote attacker to execute code. CVE-2026-71168 (CVSS score of 7.3) is a path traversal vulnerability that could enable a low-privileged local attacker to achieve remote code execution. Together, the issues show that the affected tool can expose multiple paths to privilege escalation or code execution.
The company recommends updating System Update to version 2.3.0.0 or later.
Dell has not reported any active attacks exploiting these vulnerabilities so far.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, Dell)