Dell PowerEdge Flaw Lets Attackers Run Code as root on Servers
Do you use Dell System Update to keep your PowerEdge servers up to date? Then read this article carefully. Dell has just patched five vulnerabilities in this tool, including a critical flaw that can lead to code execution with root privileges. Here’s what you need to know.
As a reminder, Dell System Update (DSU) is a command-line tool used to identify available updates (BIOS, firmware, drivers, and applications) and then deploy them on Dell PowerEdge servers. Used by system administrators, this tool is available on Linux and Windows Server. For example, if you have a Dell PowerEdge server running Windows Server, you can use it to keep the server itself up to date.
By design, Dell System Update needs to run with elevated privileges, since it interacts with firmware and the operating system. When a critical vulnerability is discovered, it becomes an attractive entry point for targeting Dell servers. That is exactly what has just happened.
CVE-2026-86360: a path traversal flaw that leads all the way to root
Dell recently published a new security bulletin describing five vulnerabilities fixed in Dell System Update. The same document also states that all versions of Dell System Update earlier than 2.3.0.0 are affected.
The most serious flaw is tracked as CVE-2026-86360 and carries a CVSS v3.1 score of 9.6 out of 10. It is a path traversal vulnerability that can be exploited remotely by an unauthenticated attacker.
"This vulnerability is considered critical because it can be exploited by an unauthenticated attacker to execute arbitrary code with root privileges", Dell says about this issue. If exploitation succeeds, both the application and the underlying operating system may be fully compromised.
The other four vulnerabilities are rated high severity:
- CVE-2026-86361 (8.2): incorrect permission assignment that allows a local attacker to escalate privileges.
- CVE-2026-86362 (8.2): an access control flaw with the same local privilege escalation scenario.
- CVE-2026-63697 (7.6): improper certificate validation, remotely exploitable, but by an attacker who already has elevated privileges. It can lead to code execution.
- CVE-2026-71168 (7.3): a second path traversal flaw, exploitable by a local attacker with low privileges, leading to code execution.
A fix available since late July
To protect yourself, you need to upgrade to Dell System Update 2.3.0.0, or a later version. However, this version is not actually new. The Dell System Update 2.3.0.0 download page notes that this release was posted on July 28, 2026, more than two months before the bulletin was published. You can also see that it is marked as "Importance: Optional," so it is not impossible that you skipped it this summer... Yet given Dell’s newly released security bulletin, it is better to install it.
As of now, Dell does not report any active exploitation of these vulnerabilities (which has not always been the case in the past).
Finally, on the same day, Dell also published a second security bulletin about Container Storage Modules (CSM), which connects its storage arrays to Kubernetes. It fixes two critical flaws in particular (CVSS scores of 10 out of 10): CVE-2026-63688 and CVE-2026-63692. Dell recommends upgrading to version 1.18.0 or later.

