Dell advisory DSA-2026-324, published 1 October 2026 and reported on 5 October, covers a critical flaw in Dell System Update. CVE-2026-86360 is a path traversal that Dell scores CVSS 9.6. Dell says an unauthenticated attacker with remote access can reach the filesystem and execute arbitrary code with root privileges.
What happened
DSU is the command-line tool enterprises use to push BIOS, firmware, and software updates onto Linux and Windows hosts in PowerEdge estates. A bug in that tool is a supply path into the servers it manages, not a desktop nuisance.
The same advisory also fixes four further DSU issues: remote code execution in CVE-2026-63697 and CVE-2026-71168, and privilege escalation in CVE-2026-86361 and CVE-2026-86362. Dell has not said these are exploited in the wild. The same day it also urged patches for two maximum-severity Container Storage Modules flaws, CVE-2026-63688 and CVE-2026-63692.
Who is affected
- Dell System Update versions before 2.3.0.0
- PowerEdge estates where DSU is reachable remotely, including management networks an attacker can already pivot into
- Linux and Windows hosts that receive BIOS, firmware, or software updates through DSU
What to do now
Upgrade Dell System Update to 2.3.0.0 or later, and confirm the DSU listener is not exposed beyond the management network. Inventory which jump hosts and automation accounts can reach it. Dell credits Ori Gabriel for CVE-2026-86360. There is no public report of in-the-wild exploitation as of this writing, so this is a patch-now item, not a confirmed intrusion.
Source: Dell DSA-2026-324.
Also on the blog
- CVE-2026-88779 crashes SAML NetScaler, patch by 7 October
- CVE-2026-104286: FortiMail path traversal, no patch yet
- Denmark CPR breach: 8.8 million identity records
- CVE-2026-61500: Rejetto HFS admin session forgery
Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.