Threat reportVulnerabilityTL-2026-2935

Dell System Update (DSU) path traversal CVE-2026-86360 (CVSS 9.6) allows unauthenticated root code execution, plus four high-severity flaws fixed in DSU 2.3.0.0

criticalPATCHED

Dell System Update (DSU) path traversal CVE-2026-86360 (CVSS (TL-2026-2935), also tracked as DSA-2026-324, is a critical-severity software vulnerability scored CVSS 9.6, first published 2026-10-05. It has no confirmed attribution, affects Dell Dell System Update (DSU), references 5 CVEs (CVE-2026-86360, CVE-2026-63697, CVE-2026-71168), maps to 5 MITRE ATT&CK techniques (T1005, T1190, T1203), and is covered by 9 detection rules and 14 indicators of compromise.

CVSS
9.6/10Critical
CVEs
5Referenced vulnerabilities
Techniques
5MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
14Indicators of compromise

Key facts for TL-2026-2935

Threat ID
TL-2026-2935
Also known as
DSA-2026-324
Severity
CRITICAL
CVSS
9.6 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H)
Status
PATCHED
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
technology, data-centers, enterprise, cloud-providers, government administration
Target regions
Global
Detection rules
9
Indicators of compromise
14

How Dell System Update (DSU) path traversal CVE-2026-86360 (CVSS works

Dell fixed five vulnerabilities in Dell System Update (DSU), the CLI firmware/driver update tool for PowerEdge servers, in advisory DSA-2026-324. The critical CVE-2026-86360 is a path traversal (CVSS 9.6) that lets an unauthenticated remote attacker run code as root; four high-severity flaws (certificate validation, path traversal, permission/access-control bugs) enable RCE and local privilege escalation. No exploitation or public PoC has been reported.

On 2026-10-01 Dell published DSA-2026-324 (KB 000515843) covering Dell System Update (DSU), the command-line tool used to deploy Dell Update Packages (firmware, BIOS and driver updates) to Dell PowerEdge servers. All DSU versions prior to 2.3.0.0 are affected by all five CVEs; DSU 2.3.0.0 or later fixes them (download driverid J9TK1). Dell recommends customers upgrade at the earliest opportunity. BleepingComputer covered the advisory on 2026-10-05.

CVE-2026-86360 (CVSS 9.6, CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H) is a path traversal weakness. Dell states that an unauthenticated attacker with remote access could potentially exploit it, leading to filesystem access; the flaw can be leveraged for arbitrary code execution with root privileges and may allow complete compromise of the vulnerable application and underlying operating system. The CVSS vector indicates user interaction is required and scope is changed; the specific trigger is not detailed in the advisory.

Four further high-severity flaws were fixed: CVE-2026-86361 (CVSS 8.2, AV:L/AC:L/PR:L/UI:R/S:C, incorrect permission assignment for a critical resource) and CVE-2026-86362 (CVSS 8.2, same vector, improper access control), both enabling local privilege escalation by a low-privileged user; CVE-2026-63697 (CVSS 7.6, AV:N/AC:H/PR:H/UI:R/S:C, improper certificate validation; a high-privileged remote attacker could achieve remote code execution); and CVE-2026-71168 (CVSS 7.3, AV:L/AC:L/PR:L/UI:R/S:U, path traversal; a low-privileged local attacker could achieve code execution). Reporters credited by Dell: Ori Gabriel (CVE-2026-63697, CVE-2026-86360), saltedfish (CVE-2026-86361, CVE-2026-86362) and Nir Yehoshua of Cipher Security Labs (CVE-2026-71168).

No active exploitation has been reported, none of the five CVEs appears in the CISA KEV catalog (catalog version 2026.10.04 checked), the NVD API returned no record for CVE-2026-86360 at research time, and no public proof-of-concept had surfaced. Dell's advisory lists no workarounds. BleepingComputer notes that state-sponsored actors have previously exploited other Dell flaws (Lazarus via CVE-2021-21551 in the dbutil driver; UNC6201 via CVE-2026-22769 in Dell RecoverPoint since mid-2024, linked to Silk Typhoon); these are historical context, not attributed to the DSU flaws. DSU runs with elevated privileges on server infrastructure, so successful exploitation would give control of firmware/driver update paths on PowerEdge hosts. No network IOCs are published; detection should focus on DSU process/file behavior and version inventory.

MITRE ATT&CK techniques used in TL-2026-2935

Collection

T1005 Data from Local System

Initial Access

T1190 Exploit Public-Facing Application

Execution

T1203 Exploitation for Client Execution

Privilege Escalation

T1548 Abuse Elevation Control Mechanism

Credential Access

T1557 Adversary-in-the-Middle

Affected products and versions in Dell System Update (DSU) path traversal CVE-2026-86360 (CVSS

  • Dell — Dell System Update (DSU)
    Vulnerable versions: All versions prior to 2.3.0.0
    Fixed in: 2.3.0.0 or later

Remediation for Dell System Update (DSU) path traversal CVE-2026-86360 (CVSS

Patches

  • DSU 2.3.0.0 or later per DSA-2026-324 (Dell KB 000515843)

Immediate actions

  • Upgrade Dell System Update (DSU) to 2.3.0.0 or later on all PowerEdge management hosts
  • Inventory DSU installations and identify any version prior to 2.3.0.0

Workarounds

  • Dell lists no workarounds; patching is the remediation
  • Hardening only (not Dell-specified): limit shell access on affected servers and remove unnecessary local accounts to reduce the local privilege escalation surface

Longer-term hardening

  • Source DSU packages and update repositories only from trusted Dell locations
  • Monitor DSU process execution and file writes on server management hosts

CVEs associated with Dell System Update (DSU) path traversal CVE-2026-86360 (CVSS

CVE-2026-86360, CVE-2026-63697, CVE-2026-71168, CVE-2026-86361, CVE-2026-86362

Weaknesses (CWE) in Dell System Update (DSU) path traversal CVE-2026-86360 (CVSS

CWE-22, CWE-295, CWE-732, CWE-284

Timeline of Dell System Update (DSU) path traversal CVE-2026-86360 (CVSS

  • Dell patches CVE-2021-21551 (dbutil driver), later abused by Lazarus Group; cited by BleepingComputer as prior state-sponsored exploitation of Dell flaws, unrelated to DSU
  • FBI and CISA urge software developers to eliminate path traversal weaknesses (May 2024 secure-by-design alert, cited by BleepingComputer)
  • Approximate (mid-2024): UNC6201 begins exploiting CVE-2026-22769 in Dell RecoverPoint; historical context, unrelated to DSU CVEs
  • Dell System Update 2.3.0.0 made available for download as the fixed version
  • Dell publishes DSA-2026-324 fixing CVE-2026-86360, CVE-2026-63697, CVE-2026-71168, CVE-2026-86361 and CVE-2026-86362 in DSU 2.3.0.0
  • CISA KEV catalog version 2026.10.04 contains none of the five DSU CVEs
  • BleepingComputer reports the DSU flaws; no active exploitation or public PoC reported; NVD API returned no record for CVE-2026-86360 at research time

Sources cited for Dell System Update (DSU) path traversal CVE-2026-86360 (CVSS

Detection coverage for TL-2026-2935

As of 2026-10-05, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2935 across Splunk SPL, Microsoft KQL and Sigma, covering 14 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
14 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats