CVE-2026-22769
CISA KEVAs of 2026-02-20, CVE-2026-22769 is a CVSS 10 (CRITICAL-severity) vulnerability. CISA KEV-listed (known exploited). EPSS exploitation probability 20.0%. Threadlinqs Intelligence tracks 2 threats exploiting it.
Last updated: 2026-02-20
Dell RecoverPoint for Virtual Machines, versions prior to 6.0.3.1 HF1, contain a hardcoded credential vulnerability. This is considered critical as an unauthenticated remote attacker with knowledge of the hardcoded credential could potentially exploit this vulnerability leading to unauthorized access to the underlying operating system and root-level persistence. Dell recommends that customers upgrade or apply one of the remediations as soon as possible.
CVSS v3 vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Weaknesses (CWE)
CWE-798
Exploitation status
CISA KEV-listed (known exploited)
Threats tracking this CVE
- Dell RecoverPoint Hardcoded Credentials RCE + UNC6201 GRIMBOLT Backdoor (CVE-2026-22769) — CRITICAL
- Dell RecoverPoint for VMs Zero-Day (CVE-2026-22769) — CVSS 10.0, PRC-Nexus UNC6201/Silk Typhoon, BRICKSTORM/GRIMBOLT/SLAYSTYLE, VMware Ghost NIC Pivoting, iptables SPA — CRITICAL
References
- https://www.dell.com/support/kbdoc/en-us/000426773/dsa-2026-079
- https://cloud.google.com/blog/topics/threat-intelligence/unc6201-exploiting-dell-recoverpoint-zero-day
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-22769
← all vulnerabilities · Markdown version · Threadlinqs Intelligence
Enriched from CVE.org, NVD (this product uses the NVD API but is not endorsed or certified by the NVD), FIRST EPSS, CISA KEV, and GitHub Security Advisories.