Vulnerability intelligence
CVE-2026-22769
Dell RecoverPoint for Virtual Machines (RP4VMs) Use of Hard-coded Credentials Vulnerability
Dell RecoverPoint for Virtual Machines (RP4VMs)
Dell RecoverPoint for Virtual Machines (RP4VMs) contains an use of hard-coded credentials vulnerability that could allow an unauthenticated remote attacker to gain unauthorized access to the underlying operating system and root-level persistence.
CVSS Score
—
Unrated
EPSS — Exploit Probability
13%
Riskier than 96% of all CVEs · checked 2026-09-04
Exploitation
Confirmed in the wild
KEV since 2026-02-18
Remediation
Unconfirmed
Federal deadline 2026-02-21
CISA required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Deadline for federal agencies: 2026-02-21.
6 articles across 5 outlets · first covered Feb 18, 2026 · latest Feb 25, 2026
Coverage timeline
-
CVE-2026-22769 in Dell RecoverPoint used to install GRIMBOLTcloud.google.com · Feb 25, 2026
-
U.S. CISA adds Dell RecoverPoint and GitLab flaws to its Known Exploited Vulnerabilities catalogsecurityaffairs.com · Feb 19, 2026
-
Dell's Hard-Coded Flaw: A Nation-State Goldminewww.darkreading.com · Feb 18, 2026
-
China-linked APT weaponized Dell RecoverPoint zero-day since 2024securityaffairs.com · Feb 18, 2026
-
Dell RecoverPoint for VMs Zero-Day CVE-2026-22769 Exploited Since Mid-2024thehackernews.com · Feb 18, 2026
-
Dell RecoverPoint Zero-Day Exploited by Chinese Cyberespionage Groupwww.securityweek.com · Feb 18, 2026