New Dell System Update flaw lets hackers gain root privileges
AI Summary
Dell has disclosed a critical vulnerability in its System Update (DSU) command-line interface tool, tracked as CVE-2026-86360, which allows unauthenticated remote attackers to exploit a path traversal weakness and execute arbitrary code with root privileges. The flaw affects Linux and Windows systems used in PowerEdge enterprise server infrastructure. Dell recommends updating DSU to version 2.3.0.0 or later to mitigate the issue. The company also patched four high-severity flaws in DSU and two maximum-severity vulnerabilities in Container Storage Modules (CSM). While no active exploitation has been confirmed, state-backed groups like Lazarus and UNC6201 have previously exploited Dell vulnerabilities.
AI-extracted · verify before operational use