securityonline.info 11 Sept 2026, 01:31 UTC

Dell Patches Four Critical OS10 Flaws Threatening Network Security

Dell Patches Four Critical OS10 Flaws Threatening Network Security

DELL has released emergency patches for four critical vulnerabilities in its Networking OS10 software, a flaw set that could let attackers steal user sessions, bypass access controls and execute arbitrary code. The disclosure notes that thousands of Dell SmartFabric OS10 devices are deployed in enterprise data centres, underscoring the potential impact on core network infrastructure.

Security researchers have confirmed there is no evidence of active exploitation or public proof-of-concept code at this time, but the combination of remote access and elevated capabilities makes timely remediation essential.

The most severe issue, CVE-2026-63695, is a session fixation flaw that an unauthenticated attacker could exploit to hijack active sessions. CVE-2026-63696 would allow a high-privilege user to download code without integrity checks, enabling remote code execution. Additional problems include CVE-2026-61418, which involves inadequate authorization that could let low-privilege remote attackers run system commands, and CVE-2026-61417, which could enable a denial-of-service condition via improper access controls.

The vulnerabilities affect multiple releases, specifically all Dell SmartFabric OS10 versions prior to 10.6.1[.]3. Dell’s patch, version 10.6.1[.]3, is available via the official support portal, and the vendor’s security update documentation provides deployment guidance. At present, the advisory states there are no workarounds for these flaws. Administrators are urged to apply the update promptly to reduce risk across affected networks.

View full article

Article by CyberSIXT