Skip to content
TrustList
News

Dell System Update 2.3.0.0 fixes a critical unauthenticated root code-execution flaw (CVE-2026-86360) and four high-severity bugs

Editorial

By TrustList Editorial

Dell advisory DSA-2026-324 covers five flaws in the Dell System Update (DSU) tool used to push firmware to PowerEdge servers. Every version before 2.3.0.0 is affected; Dell has not reported exploitation.

About Dell System Update 2.3.0.0 fixes a critical unauthenticated root code-execution flaw (CVE-2026-86360) and four high-severity bugs

Dell System Update 2.3.0.0 fixes a critical unauthenticated root code-execution flaw (CVE-2026-86360) and four high-severity bugs

1 October 2026 — Dell published security advisory DSA-2026-324 on 1 October 2026 for Dell System Update (DSU), the command-line tool that administrators use to deploy BIOS, firmware and software updates to PowerEdge servers on Linux and Windows. The advisory covers five vulnerabilities, one of them rated critical. Dell tells customers to move to DSU 2.3.0.0 or later.

Not yet independently verified. We could not open Dell's own advisory page (403 to our fetch), so the affected-version and fixed-version statements rest on BleepingComputer's report of Dell's advisory and on the advisory number and URL quoted by SecurityOnline. Dell is reported to have said it has not seen exploitation; no CISA KEV entry for these CVEs was present in the catalogue we read on 2026-10-05. Severity scores were not independently checked. We will update this when it can be confirmed, and remove this note.

What changed

The critical flaw, CVE-2026-86360, is a path traversal weakness. Dell describes it as exploitable by an unauthenticated attacker with remote access, and says it can lead to execution of arbitrary code with root privileges on an unpatched system, with possible complete compromise of the application and the operating system underneath it.

Four further flaws were fixed in the same release. According to BleepingComputer's reading of the advisory, two of them (CVE-2026-63697 and CVE-2026-71168) can be used by remote attackers to run code, and two (CVE-2026-86361 and CVE-2026-86362) allow privilege escalation. Dell recommends that customers upgrade at the earliest opportunity.

Dell has not flagged any of the five as exploited. BleepingComputer notes that other Dell products have been abused by state-backed groups in recent years, which is a reason to treat a root-level flaw in a server management tool as urgent even without confirmed attacks. On the same day Dell also published fixes for two maximum-severity flaws in its Container Storage Modules; TrustList has covered that advisory separately.

Who is affected

Any organisation that runs Dell System Update on PowerEdge servers, whether on Linux or Windows, and has not yet installed version 2.3.0.0 or later. Because DSU is typically installed on many hosts and runs with high privileges, the practical exposure depends on how the tool is reached. Teams that run it only interactively on a management network have a smaller attack surface than teams that leave it available to wider networks, but the advisory language about remote, unauthenticated access means that assumption should be checked, not trusted.

Managed service providers and hosting firms that standardise on PowerEdge fleets, and any team whose configuration management copies an older DSU installer onto new servers, should look at their build images as well as their running hosts.

What to do

  • Inventory the DSU version on every PowerEdge host, including golden images, provisioning scripts and offline installer repositories.
  • Upgrade to DSU 2.3.0.0 or later, following the instructions in Dell advisory DSA-2026-324.
  • Check where DSU is reachable from. If any instance is exposed beyond a management network, restrict it until it is patched.
  • Review logs on hosts that ran an older DSU for unexpected file access or new processes started by the tool.
  • Record the change against the five CVE numbers so audit and vulnerability scanners can close the findings.

Why it matters

Server lifecycle tools sit in a trusted position: they have root, they touch firmware, and they are often exempt from the controls applied to ordinary applications. A critical flaw there is rarely noisy, and a compromise can persist below the operating system. Buyers who rely on Dell, or on a provider that manages Dell hardware for them, can ask for confirmation that DSU has been updated, and for the date it was done.

Company profile on TrustList: Dell

Sources

Categories & features