Dell System Update flaw allows attackers to gain root privileges (CVE-2026-86360)
Dell System Update flaw CVE-2026-86360 can let unauthenticated remote attackers execute code as root.
Dell urged customers to patch CVE-2026-86360, a path-traversal vulnerability in Dell System Update before version 2.3.0.0 with a CVSS base score of 9.6. An unauthenticated remote attacker could gain filesystem access and execute arbitrary code as root, potentially compromising the application and the underlying operating system. DSU applies driver, BIOS, and firmware updates to Dell PowerEdge servers. Dell also fixed CVE-2026-63697 and CVE-2026-71168, which could allow remote execution, and CVE-2026-86361 and CVE-2026-86362, which could allow privilege elevation. The advisory does not say any of the flaws have been exploited in the wild.
- CVE-2026-86360 is an unauthenticated remote path traversal scored CVSS 9.6.
- Successful exploitation can execute arbitrary code with root privileges.
- DSU versions before 2.3.0.0 are affected on PowerEdge update workflows.
- Four other high-severity remote-execution or privilege flaws were fixed.
- Dell does not report exploitation in the wild.
Vulnerabilities mentionedAll →
- CVE-2026-863609.6—Unauthenticated Path Traversal to Root Code Execution in Dell System Updatepublished · Dell System Update (DSU)+4 related
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
CVE-2026-86360+4 related CVEs | Unauthenticated Path Traversal to Root Code Execution in Dell System Update |
Full article231 words · extracted from helpnetsecurity.com · click to collapse
Dell is urging customers to patch a vulnerability (CVE-2026-86360) in Dell System Update (DSU) that could allow an unauthenticated remote attacker to execute arbitrary code with root privileges.

DSU is a tool used by enterprise IT administrators to apply driver, BIOS, and firmware updates to Dell PowerEdge servers.
About CVE-2026-86360
CVE-2026-86360 is a path traversal vulnerability with a CVSS base score of 9.6 that affects DSU versions prior to 2.3.0.0.
“An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access for attacker. This vulnerability is considered critical because it can be leveraged by an unauthenticated attacker to execute arbitrary code with root privileges,” the company wrote in the advisory.
According to Dell, successful exploitation may lead to complete compromise of the vulnerable application and the underlying operating system.
“Dell recommends customers upgrade at the earliest opportunity,” the company noted, advising users to update to DSU version 2.3.0.0 or later.
Four more vulnerabilities fixed
Dell fixed four other high-severity flaws in DSU. Two of them (CVE-2026-63697 and CVE-2026-71168) could lead to remote execution, and the other two (CVE-2026-86361 and CVE-2026-86362) could let attackers elevate their privileges.
Ori Gabriel reported CVE-2026-86360 and CVE-2026-63697. A researcher using the name saltedfish reported CVE-2026-86361 and CVE-2026-86362, and Nir Yehoshua of Cipher Security Labs reported CVE-2026-71168.
The advisory does not say whether any of the vulnerabilities have been exploited in the wild.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2026/10/06/dell-system-update-vulnerability-cve-2026-86360/