Dell System Update 2.3.0.0 fixes a critical unauthenticated root code-execution flaw (CVE-2026-86360) and four high-severity bugs
EditorialBy TrustList Editorial
Dell advisory DSA-2026-324 covers five flaws in the Dell System Update (DSU) tool used to push firmware to PowerEdge servers. Every version before 2.3.0.0 is affected; Dell has not reported exploitation.
- Cybersecurity
- Vulnerability Management
- Patch Management
About Dell System Update 2.3.0.0 fixes a critical unauthenticated root code-execution flaw (CVE-2026-86360) and four high-severity bugs
Dell System Update 2.3.0.0 fixes a critical unauthenticated root code-execution flaw (CVE-2026-86360) and four high-severity bugs
1 October 2026 — Dell published security advisory DSA-2026-324 on 1 October 2026 for Dell System Update (DSU), the command-line tool that administrators use to deploy BIOS, firmware and software updates to PowerEdge servers on Linux and Windows. The advisory covers five vulnerabilities, one of them rated critical. Dell tells customers to move to DSU 2.3.0.0 or later.
Not yet independently verified. We could not open Dell's own advisory page (403 to our fetch), so the affected-version and fixed-version statements rest on BleepingComputer's report of Dell's advisory and on the advisory number and URL quoted by SecurityOnline. Dell is reported to have said it has not seen exploitation; no CISA KEV entry for these CVEs was present in the catalogue we read on 2026-10-05. Severity scores were not independently checked. We will update this when it can be confirmed, and remove this note.
What changed
The critical flaw, CVE-2026-86360, is a path traversal weakness. Dell describes it as exploitable by an unauthenticated attacker with remote access, and says it can lead to execution of arbitrary code with root privileges on an unpatched system, with possible complete compromise of the application and the operating system underneath it.
Four further flaws were fixed in the same release. According to BleepingComputer's reading of the advisory, two of them (CVE-2026-63697 and CVE-2026-71168) can be used by remote attackers to run code, and two (CVE-2026-86361 and CVE-2026-86362) allow privilege escalation. Dell recommends that customers upgrade at the earliest opportunity.
Dell has not flagged any of the five as exploited. BleepingComputer notes that other Dell products have been abused by state-backed groups in recent years, which is a reason to treat a root-level flaw in a server management tool as urgent even without confirmed attacks. On the same day Dell also published fixes for two maximum-severity flaws in its Container Storage Modules; TrustList has covered that advisory separately.
Who is affected
Any organisation that runs Dell System Update on PowerEdge servers, whether on Linux or Windows, and has not yet installed version 2.3.0.0 or later. Because DSU is typically installed on many hosts and runs with high privileges, the practical exposure depends on how the tool is reached. Teams that run it only interactively on a management network have a smaller attack surface than teams that leave it available to wider networks, but the advisory language about remote, unauthenticated access means that assumption should be checked, not trusted.
Managed service providers and hosting firms that standardise on PowerEdge fleets, and any team whose configuration management copies an older DSU installer onto new servers, should look at their build images as well as their running hosts.
What to do
- Inventory the DSU version on every PowerEdge host, including golden images, provisioning scripts and offline installer repositories.
- Upgrade to DSU 2.3.0.0 or later, following the instructions in Dell advisory DSA-2026-324.
- Check where DSU is reachable from. If any instance is exposed beyond a management network, restrict it until it is patched.
- Review logs on hosts that ran an older DSU for unexpected file access or new processes started by the tool.
- Record the change against the five CVE numbers so audit and vulnerability scanners can close the findings.
Why it matters
Server lifecycle tools sit in a trusted position: they have root, they touch firmware, and they are often exempt from the controls applied to ordinary applications. A critical flaw there is rarely noisy, and a compromise can persist below the operating system. Buyers who rely on Dell, or on a provider that manages Dell hardware for them, can ask for confirmation that DSU has been updated, and for the date it was done.
Company profile on TrustList: Dell
Sources
Categories & features
- Cybersecurity
- Vulnerability Management
- Patch Management
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- More CybersecurityThe ranking for this subject
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.