Threat reportVulnerabilityTL-2026-2935
Dell System Update (DSU) path traversal CVE-2026-86360 (CVSS 9.6) allows unauthenticated root code execution, plus four high-severity flaws fixed in DSU 2.3.0.0
Dell System Update (DSU) path traversal CVE-2026-86360 (CVSS (TL-2026-2935), also tracked as DSA-2026-324, is a critical-severity software vulnerability scored CVSS 9.6, first published 2026-10-05. It has no confirmed attribution, affects Dell Dell System Update (DSU), references 5 CVEs (CVE-2026-86360, CVE-2026-63697, CVE-2026-71168), maps to 5 MITRE ATT&CK techniques (T1005, T1190, T1203), and is covered by 9 detection rules and 14 indicators of compromise.
- CVSS
- 9.6/10Critical
- CVEs
- 5Referenced vulnerabilities
- Techniques
- 5MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 14Indicators of compromise
Key facts for TL-2026-2935
- Threat ID
- TL-2026-2935
- Also known as
- DSA-2026-324
- Severity
- CRITICAL
- CVSS
- 9.6 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H)
- Status
- PATCHED
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- technology, data-centers, enterprise, cloud-providers, government administration
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 14
How Dell System Update (DSU) path traversal CVE-2026-86360 (CVSS works
Dell fixed five vulnerabilities in Dell System Update (DSU), the CLI firmware/driver update tool for PowerEdge servers, in advisory DSA-2026-324. The critical CVE-2026-86360 is a path traversal (CVSS 9.6) that lets an unauthenticated remote attacker run code as root; four high-severity flaws (certificate validation, path traversal, permission/access-control bugs) enable RCE and local privilege escalation. No exploitation or public PoC has been reported.
On 2026-10-01 Dell published DSA-2026-324 (KB 000515843) covering Dell System Update (DSU), the command-line tool used to deploy Dell Update Packages (firmware, BIOS and driver updates) to Dell PowerEdge servers. All DSU versions prior to 2.3.0.0 are affected by all five CVEs; DSU 2.3.0.0 or later fixes them (download driverid J9TK1). Dell recommends customers upgrade at the earliest opportunity. BleepingComputer covered the advisory on 2026-10-05.
CVE-2026-86360 (CVSS 9.6, CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H) is a path traversal weakness. Dell states that an unauthenticated attacker with remote access could potentially exploit it, leading to filesystem access; the flaw can be leveraged for arbitrary code execution with root privileges and may allow complete compromise of the vulnerable application and underlying operating system. The CVSS vector indicates user interaction is required and scope is changed; the specific trigger is not detailed in the advisory.
Four further high-severity flaws were fixed: CVE-2026-86361 (CVSS 8.2, AV:L/AC:L/PR:L/UI:R/S:C, incorrect permission assignment for a critical resource) and CVE-2026-86362 (CVSS 8.2, same vector, improper access control), both enabling local privilege escalation by a low-privileged user; CVE-2026-63697 (CVSS 7.6, AV:N/AC:H/PR:H/UI:R/S:C, improper certificate validation; a high-privileged remote attacker could achieve remote code execution); and CVE-2026-71168 (CVSS 7.3, AV:L/AC:L/PR:L/UI:R/S:U, path traversal; a low-privileged local attacker could achieve code execution). Reporters credited by Dell: Ori Gabriel (CVE-2026-63697, CVE-2026-86360), saltedfish (CVE-2026-86361, CVE-2026-86362) and Nir Yehoshua of Cipher Security Labs (CVE-2026-71168).
No active exploitation has been reported, none of the five CVEs appears in the CISA KEV catalog (catalog version 2026.10.04 checked), the NVD API returned no record for CVE-2026-86360 at research time, and no public proof-of-concept had surfaced. Dell's advisory lists no workarounds. BleepingComputer notes that state-sponsored actors have previously exploited other Dell flaws (Lazarus via CVE-2021-21551 in the dbutil driver; UNC6201 via CVE-2026-22769 in Dell RecoverPoint since mid-2024, linked to Silk Typhoon); these are historical context, not attributed to the DSU flaws. DSU runs with elevated privileges on server infrastructure, so successful exploitation would give control of firmware/driver update paths on PowerEdge hosts. No network IOCs are published; detection should focus on DSU process/file behavior and version inventory.
MITRE ATT&CK techniques used in TL-2026-2935
Collection
Initial Access
T1190 Exploit Public-Facing Application
Execution
T1203 Exploitation for Client Execution
Privilege Escalation
T1548 Abuse Elevation Control Mechanism
Credential Access
Affected products and versions in Dell System Update (DSU) path traversal CVE-2026-86360 (CVSS
- Dell — Dell System Update (DSU)
Vulnerable versions: All versions prior to 2.3.0.0
Fixed in: 2.3.0.0 or later
Remediation for Dell System Update (DSU) path traversal CVE-2026-86360 (CVSS
Patches
- DSU 2.3.0.0 or later per DSA-2026-324 (Dell KB 000515843)
Immediate actions
- Upgrade Dell System Update (DSU) to 2.3.0.0 or later on all PowerEdge management hosts
- Inventory DSU installations and identify any version prior to 2.3.0.0
Workarounds
- Dell lists no workarounds; patching is the remediation
- Hardening only (not Dell-specified): limit shell access on affected servers and remove unnecessary local accounts to reduce the local privilege escalation surface
Longer-term hardening
- Source DSU packages and update repositories only from trusted Dell locations
- Monitor DSU process execution and file writes on server management hosts
CVEs associated with Dell System Update (DSU) path traversal CVE-2026-86360 (CVSS
CVE-2026-86360, CVE-2026-63697, CVE-2026-71168, CVE-2026-86361, CVE-2026-86362
Weaknesses (CWE) in Dell System Update (DSU) path traversal CVE-2026-86360 (CVSS
Timeline of Dell System Update (DSU) path traversal CVE-2026-86360 (CVSS
- Dell patches CVE-2021-21551 (dbutil driver), later abused by Lazarus Group; cited by BleepingComputer as prior state-sponsored exploitation of Dell flaws, unrelated to DSU
- FBI and CISA urge software developers to eliminate path traversal weaknesses (May 2024 secure-by-design alert, cited by BleepingComputer)
- Approximate (mid-2024): UNC6201 begins exploiting CVE-2026-22769 in Dell RecoverPoint; historical context, unrelated to DSU CVEs
- Dell System Update 2.3.0.0 made available for download as the fixed version
- Dell publishes DSA-2026-324 fixing CVE-2026-86360, CVE-2026-63697, CVE-2026-71168, CVE-2026-86361 and CVE-2026-86362 in DSU 2.3.0.0
- CISA KEV catalog version 2026.10.04 contains none of the five DSU CVEs
- BleepingComputer reports the DSU flaws; no active exploitation or public PoC reported; NVD API returned no record for CVE-2026-86360 at research time
Sources cited for Dell System Update (DSU) path traversal CVE-2026-86360 (CVSS
- New Dell System Update flaw lets hackers gain root privileges
- DSA-2026-324: Dell System Update security advisory
- Dell System Update 2.3.0.0 download
- Dell System Update Flaw CVE-2026-86360 Could Allow Root Code Execution
- CVE-2026-86362 - vulnerability database
- CVE-2026-86361 - vulnerability database
- Dell System Update (DSU) product documentation
- CISA Known Exploited Vulnerabilities Catalog
- NVD CVE API record query for CVE-2026-86360
Detection coverage for TL-2026-2935
As of 2026-10-05, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2935 across Splunk SPL, Microsoft KQL and Sigma, covering 14 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.