Dell has warned customers about a critical vulnerability in its System Update (DSU) command-line interface (CLI) deployment tool, which allows hackers to gain root privileges on unpatched devices. The flaw, tracked as CVE-2026-86360, is considered critical because it can be exploited by an unauthenticated attacker to execute arbitrary code with root privileges.
The DSU tool is used by enterprise IT administrators to deploy BIOS, firmware, and software updates onto Linux and Windows systems running on PowerEdge enterprise servers. The vulnerability allows hackers to bypass security controls and gain access to sensitive areas of the system, potentially leading to a complete compromise of the vulnerable application and underlying operating system.
Dell’s security advisory warns that an unauthenticated attacker with remote access could exploit this vulnerability, leading to filesystem access for the attacker. This is particularly concerning because it means that hackers can gain root privileges without needing any login credentials or authentication.
The FBI and CISA have been warning software companies about the dangers of path traversal weaknesses since at least 2007. These types of vulnerabilities allow attackers to bypass security controls and access sensitive areas of a system by manipulating file paths. Dell’s patching of four high-severity DSU security flaws, including two that can be exploited for remote code execution and two more that can be abused for privilege escalation, is a welcome step in addressing this issue.
State-backed hacking groups have been known to exploit vulnerabilities in Dell products in the past. For example, the North Korean Lazarus group used an insufficient access control vulnerability in the dbutil driver to deploy a Windows rootkit on victims’ systems. More recently, suspected Chinese cyber spies exploited a hardcoded-credential vulnerability in Dell RecoverPoint for Virtual Machines to create hidden network interfaces and deploy malware payloads.
Dell recommends that customers upgrade to DSU version 2.3.0.0 or later, which patches the flaws. IT administrators are also advised to patch two maximum-severity Container Storage Modules (CSM) vulnerabilities as soon as possible.
While there is no indication that these vulnerabilities have been actively exploited, it’s essential for organizations to take immediate action to protect their systems. With the rise of state-backed hacking groups and the increasing sophistication of cyber threats, it’s crucial for IT administrators to stay vigilant and keep software up-to-date with the latest security patches.
To avoid falling victim to such attacks, we recommend that organizations prioritize regular software updates and patching. This includes not only DSU but also other critical systems and applications. Regular vulnerability assessments and penetration testing can also help identify potential weaknesses and prevent exploits. By staying proactive and informed about emerging threats, you can better protect your organization from the ever-evolving landscape of cyber threats.
Source: Bleeping Computer — 2026-10-05