DELL has urged customers to patch a critical flaw in its System Update (DSU) tool that could let unauthenticated attackers run code with root privileges on PowerEdge servers. The vulnerability, CVE-2026-86360, is a path traversal flaw in DSU versions prior to 2.3.0[.]0. Dell warns that an attacker with remote access could exploit this issue to achieve filesystem access and potentially take complete control of the vulnerable system.
The advisory emphasises that DSU is used to deploy BIOS, firmware and software updates on Linux and Windows servers, underscoring the broad impact of an unpatched instance.
Beyond the critical CVE-2026-86360 flaw, Dell also addressed four additional vulnerabilities in DSU prior to 2.3.0[.]0. These include CVE-2026-86361 and CVE-2026-86362, both rated 8.2, which could allow a low-privileged local attacker to escalate privileges due to incorrect permissions or access controls. CVE-2026-63697, rated 7.6, concerns improper certificate validation that could enable a highly privileged remote attacker to execute code.
CVE-2026-71168, rated 7.3, is another path traversal issue that could permit a low-privileged local attacker to achieve remote code execution. Dell states there have been no reported active exploits at this time.
Dell recommends upgrading DSU to version 2.3.0[.]0 or later. The firm notes that there is currently no evidence of ongoing exploitation, but urges immediate patching to prevent potential compromise of affected PowerEdge environments.