DELL has released a security update on 9 September 2026 addressing seven ThinOS vulnerabilities. The flaws enable remote attackers to execute arbitrary commands and bypass protections, with the most severe being CVE-2026-81467, which has a CVSSv3 score of 9.8. Dell notes that ThinOS 10 remediation is available for multiple issues that could be exploited to compromise affected devices. The advisory states that all seven flaws have been fixed in ThinOS version 2605_10.2616.
The vulnerabilities are distributed as seven CVEs, including CVE-2026-81467 (9.8, CWE-78), CVE-2026-81048 (9.6, CWE-77), CVE-2026-81046 (9.4, CWE-284), CVE-2026-81468 (9.1, CWE-78), CVE-2026-81052 (6.8, CWE-494), CVE-2026-81051 (6.6, CWE-1328), and CVE-2026-81049 (4.4, CWE-353). Notably, none are currently marked as exploited in the wild, and there is no public proof-of-concept across these flaws. Affected products are all Dell ThinOS 10 releases prior to 2605_10.2616.
In terms of practical response, the guidance is to deploy the 2605_10.2616 update across all impacted devices and review the Dell security update for ThinOS 10 for installation instructions. Organisations are also advised to segment thin clients into isolated network zones until patches are in place.
The article emphasises that, given the scale of thin client deployments in sectors such as healthcare and finance, timely patching is essential to prevent potential compromises that could enable keystroke capture, traffic interception, or lateral movement into internal networks.