# Dell vulnerabilities & exploitation

**CISA KEV**

> As of 2026-10-05, Threadlinqs tracks 5 Dell CVEs, 1 in the CISA Known Exploited Vulnerabilities catalog, linked to 7 tracked threat campaigns and 1 named threat actor.

**Data as of:** 2026-10-05

## Exploitation timeline

Threadlinqs has recorded 5 Dell CVEs published between 2026-02-15 and 2026-07-15. The busiest month was 2026-06 (3 new CVEs). 1 of them (20%) are listed in CISA KEV, which means exploitation in the wild has been confirmed.

## Most exploited vulnerabilities

Ranked with CISA KEV listings first, then EPSS exploit probability, then CVSS score. Showing 5 of 5 tracked Dell CVEs.

- [CVE-2026-22769](https://intel.threadlinqs.com/cve/CVE-2026-22769) — CRITICAL 10 · KEV · EPSS 20% · 2026-02-17
- [CVE-2026-53483](https://intel.threadlinqs.com/cve/CVE-2026-53483) — CRITICAL 9.8 · EPSS 0.6% · 2026-07-07
- [CVE-2026-35069](https://intel.threadlinqs.com/cve/CVE-2026-35069) — MEDIUM 5.7 · EPSS 0.2% · 2026-06-17
- [CVE-2026-35068](https://intel.threadlinqs.com/cve/CVE-2026-35068) — LOW 3.5 · EPSS 0.2% · 2026-06-17
- [CVE-2026-32652](https://intel.threadlinqs.com/cve/CVE-2026-32652) — HIGH 7.8 · 2026-06-17

## Products affected

Threadlinqs normalises CPE and CNA product records across all 5 CVEs; 4 distinct Dell products are affected. The most frequently affected:

- PowerFlex — 2 CVEs
- AIOps — 1 CVE
- PowerProtect Data Domain — 1 CVE
- Recoverpoint For Virtual Machines — 1 CVE

## Threat activity

7 tracked threat campaigns reference Dell products or exploit Dell CVEs:

- [Dell Container Storage Modules (CSM) flaws enable unauthenticated admin access and root on Kubernetes nodes (CVE-2026-63688, CVE-2026-63692, CVE-2026-67269, CVE-2026-54472, CVE-2026-61421, CVE-2026-67273)](https://intel.threadlinqs.com/threat/TL-2026-2851) — CRITICAL — 2026-10-02
- [Chinese-speaking threat group UAT-10147 uses agentic AI to automate exploitation of internet-facing web servers](https://intel.threadlinqs.com/threat/TL-2026-2096) — HIGH — 2026-08-21
- [Dell PowerProtect Data Domain Multiple Vulnerabilities: Improper Authentication (CVE-2026-53483) and Path Traversal (CVE-2026-53481) Allow Full Remote System Access](https://intel.threadlinqs.com/threat/TL-2026-1371) — CRITICAL — 2026-07-15
- [Dell BIOS Flaw (CVE-2026-40639 / DSA-2026-197) Lets Attackers Recover Admin Passwords From SPI Flash](https://intel.threadlinqs.com/threat/TL-2026-1200) — HIGH — 2026-07-11
- [Dell Wyse Management Suite Critical RCE Chain (CVE-2026-41120, CVE-2026-49506)](https://intel.threadlinqs.com/threat/TL-2026-1204) — CRITICAL — 2026-07-11
- [Dell RecoverPoint Hardcoded Credentials RCE + UNC6201 GRIMBOLT Backdoor (CVE-2026-22769)](https://intel.threadlinqs.com/threat/TL-2026-0194) — CRITICAL — 2026-03-07
- [Dell RecoverPoint for VMs Zero-Day (CVE-2026-22769) — CVSS 10.0, PRC-Nexus UNC6201/Silk Typhoon, BRICKSTORM/GRIMBOLT/SLAYSTYLE, VMware Ghost NIC Pivoting, iptables SPA](https://intel.threadlinqs.com/threat/TL-2026-0123) — CRITICAL — 2026-02-21

## Threat actors targeting Dell

Named threat actors attributed to campaigns that involve Dell products or CVEs, with the number of linked campaigns:

- [UNC6201](https://intel.threadlinqs.com/actor/UNC6201) — 2 campaigns

## How to prioritise Dell patching

This order follows the data Threadlinqs holds for Dell, not a generic severity checklist:

- 1 of 5 Dell CVEs (20%) are in CISA KEV: treat them as actively exploited and remediate them first, starting with [CVE-2026-22769](https://intel.threadlinqs.com/cve/CVE-2026-22769).
- Outside KEV, the highest EPSS scores are [CVE-2026-53483](https://intel.threadlinqs.com/cve/CVE-2026-53483) (0.6%), [CVE-2026-35069](https://intel.threadlinqs.com/cve/CVE-2026-35069) (0.2%), [CVE-2026-35068](https://intel.threadlinqs.com/cve/CVE-2026-35068) (0.2%).
- 2 CVEs score Critical and 1 High on CVSS v3 (maximum 10, average 7.4); sequence these after KEV and high-EPSS items.

## About this data

Vendor attribution comes from the CNA and CPE product records of each CVE, folded to one vendor name; CVSS, EPSS and KEV status are read from the Threadlinqs CVE catalog; campaign and actor links come from tracked threat records. Counts reflect the data as of 2026-10-05 and refresh daily.

Canonical: https://intel.threadlinqs.com/vendors/dell
All vendors: https://intel.threadlinqs.com/vendors
Full detection coverage and IOCs via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
