Dell Urges Customers to Patch Critical DSU Flaw That Can Give Attackers Root Access

Dell warns that a critical DSU flaw lets attackers run code as root. Customers should patch affected PowerEdge systems as soon as possible.
Dell urged customers to patch a critical flaw, tracked as CVE-2026-86360 (CVSS score of 9.6), in its System Update (DSU) tool. The vulnerability is a path traversal issue that can let attackers execute code with root privileges on unpatched PowerEdge servers. This flaw could give attackers full control of vulnerable servers. DSU is used by enterprise IT teams to deploy BIOS, firmware and software updates on Linux and Windows systems. The vendor recommends applying the available security updates as soon as possible to prevent exploitation.
“Dell System Update, versions prior to 2.3.0.0, contains an Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access for attacker.” reads the advisory. “This vulnerability is considered critical because it can be leveraged by an unauthenticated attacker to execute arbitrary code with root privileges. Successful exploitation may allow complete compromise of the vulnerable application and underlying operating system. Dell recommends customers upgrade at the earliest opportunity.”
Beyond the critical CVE-2026-86360 flaw, Dell addressed four other vulnerabilities in System Update versions before 2.3.0.0. CVE-2026-86361 and CVE-2026-86362, both rated 8.2, could allow a low-privileged local attacker to gain higher privileges by exploiting incorrect permissions or access controls. CVE-2026-63697 (CVSS score of 7.6) is an improper certificate validation flaw that could allow a highly privileged remote attacker to execute code. CVE-2026-71168 (CVSS score of 7.3) is a path traversal vulnerability that could enable a low-privileged local attacker to achieve remote code execution. Together, the issues show that the affected tool can expose multiple paths to privilege escalation or code execution.
The company recommends updating System Update to version 2.3.0.0 or later.
Dell has not reported any active attacks exploiting these vulnerabilities so far.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
Pierluigi Paganini
(SecurityAffairs – hacking, Dell)

