New Dell System Update flaw lets hackers gain root privileges
Key Points:
- Dell has issued a critical security advisory urging customers to patch a vulnerability (CVE-2026-86360) in its System Update (DSU) CLI tool, which allows remote, unauthenticated attackers to execute code with root privileges via a path traversal flaw.
- The DSU tool is used by enterprise IT administrators to deploy BIOS, firmware, and software updates on Linux and Windows systems within PowerEdge server infrastructure.
- Alongside the critical flaw, Dell patched four other high-severity DSU vulnerabilities affecting remote code execution and privilege escalation, recommending immediate updates to DSU version 2.3.0.0 or later.
- Dell also warned about two maximum-severity vulnerabilities in Container Storage Modules (CSM) that require urgent patching, though none of the new flaws have been reported as actively exploited yet.
- The advisory highlights previous exploitation of Dell vulnerabilities by state-backed groups, including North Korea’s Lazarus group and suspected Chinese cyber spies linked to espionage campaigns targeting government agencies.