Dell System Update (DSU) CVE-2026-86360 (CVSS 9.6): unauthenticated path traversal → code execution as root on PowerEdge update tooling — plus four Highs; patch DSU 2.3.0.0
Dell's DSA-2026-324 (1 Oct 2026) fixes five flaws in Dell System Update, the command-line tool admins use to push BIOS, firmware and driver updates to PowerEdge servers on Linux and Windows. The critical one, CVE-2026-86360 (CVSS 3.1 9.6), is a path traversal that an unauthenticated remote attacker could use for filesystem access; Dell says it can be leveraged to run arbitrary code with root privileges and fully compromise the application and the underlying operating system. The same release fixes CVE-2026-86361 and CVE-2026-86362 (both 8.2, local low-privileged elevation of privilege), CVE-2026-63697 (7.6, improper certificate validation leading to remote execution by a high-privileged attacker) and CVE-2026-71168 (7.3, local path traversal leading to code execution). Dell has not flagged any of them as exploited. Reporters credited by Dell: Ori Gabriel, saltedfish, and Nir Yehoshua of Cipher Security Labs. Wire: BleepingComputer 5 Oct.
- Product
- Dell System Update (DSU) — PowerEdge BIOS/firmware/driver update CLI for Linux and Windows
- Versions
- Affected: DSU versions prior to 2.3.0.0. Fixed: 2.3.0.0 or later. CVEs: CVE-2026-86360 (9.6), CVE-2026-86361 (8.2), CVE-2026-86362 (8.2), CVE-2026-63697 (7.6), CVE-2026-71168 (7.3).
- CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H- Exploited in Australia?
- unknown
- Patch to
- Upgrade Dell System Update to 2.3.0.0 or later on every PowerEdge host and update repository server per DSA-2026-324. Until then, keep DSU off untrusted networks and limit who can run it or reach its catalogue and repository paths.
Primary: Dell — DSA-2026-324: Security update for Dell System Update (DSU) vulnerabilities (1 Oct 2026) · Vendor: Dell — Dell System Update 2.3.0.0 download · CVE: CVE-2026-86360, CVE-2026-86361, CVE-2026-86362, CVE-2026-63697, CVE-2026-71168 · BleepingComputer — New Dell System Update flaw lets hackers gain root privileges (5 Oct 2026)
