cloud.google.com 2/25/2026, 3:57:30 PM · external

CVE-2026-22769 in Dell RecoverPoint used to install GRIMBOLT

CVE-2026-22769 in Dell RecoverPoint used to install GRIMBOLT
CyberSIXT Evidence Panel
Primary Source dell.com
CISA KEV Listed in KEV
Patch Patch Available
Threat Actor
UNC6201

MANDIANT and Google Threat Intelligence Group identified a critical zero-day vulnerability (CVE-2026-22769) in Dell RecoverPoint for Virtual Machines, with a CVSS score of 10.0, exploited by the UNC6201 threat cluster since mid-2024 for lateral movement and deploying malware like GRIMBOLT. GRIMBOLT replaces older BRICKSTORM binaries, using C# and AOT compilation to enhance stealth and performance.

The report details the exploitation mechanisms, including unauthorized access via Tomcat Manager due to default credentials, and new tactics like 'Ghost NICs' for network pivoting. Remediation guidance and actionable insights for incident responders are provided, alongside detection indicators for community use.

View Primary Source Via cloud.google.com

Article by CyberSIXT