Dell has issued an urgent advisory to customers, recommending they patch a critical vulnerability in its System Update (DSU) tool that could allow attackers to gain root access on affected PowerEdge servers. The flaw, identified as CVE-2026-86360, carries a CVSS score of 9.6, indicating its severe potential impact.
The vulnerability is a path traversal issue present in Dell System Update versions prior to 2.3.0.0. It could enable an unauthenticated attacker with remote access to execute arbitrary code with root privileges, potentially leading to a complete compromise of the vulnerable application and the underlying operating system. DSU is widely used by enterprise IT teams to deploy BIOS, firmware, and software updates on both Linux and Windows systems.
Dell's advisory specifically states that successful exploitation of CVE-2026-86360 could grant attackers filesystem access and full control over vulnerable servers. The company emphasizes the importance of applying the available security updates as soon as possible to mitigate the risk of exploitation.
In addition to the critical CVE-2026-86360, Dell addressed four other vulnerabilities in DSU versions preceding 2.3.0.0. Two of these, CVE-2026-86361 and CVE-2026-86362, are rated 8.2 and involve incorrect permissions or access controls that a low-privileged local attacker could exploit to achieve privilege escalation.
Another significant flaw, CVE-2026-63697, has a CVSS score of 7.6 and concerns improper certificate validation. This could allow a highly privileged remote attacker to execute code. Lastly, CVE-2026-71168, with a CVSS score of 7.3, is another path traversal vulnerability that could enable a low-privileged local attacker to achieve remote code execution.
Collectively, these vulnerabilities highlight multiple potential avenues for privilege escalation or code execution within the Dell System Update tool. Dell recommends that all customers upgrade their System Update installations to version 2.3.0.0 or later without delay.
As of the latest reports, Dell has not indicated any active exploitation of these vulnerabilities in the wild.






