A Dell utility used to keep enterprise servers updated contains a critical flaw that could instead give an attacker root-level control.
Dell disclosed five vulnerabilities in Dell System Update, including a 9.6-rated path traversal flaw that could allow an unauthenticated remote attacker to execute arbitrary code with root privileges on affected systems.
Dell has released fixes and says it has seen no evidence of active exploitation. Because DSU operates with elevated privileges on server infrastructure, however, organizations running affected versions should prioritize the update.
Five Dell System Update flaws range from high to critical severity
According to Dell’s security advisory dated Oct. 1, all five vulnerabilities carry CVSS scores ranging from 9.6 to 7.3.
One is rated Critical, and the remaining four are rated High. While their severity and attack requirements differ, each can lead to privilege escalation or code execution on affected systems.
The most serious, CVE-2026-86360, is a Path Traversal flaw rated 9.6 that could allow an unauthenticated attacker with remote access to gain filesystem access and ultimately execute arbitrary code with root privileges. Dell says successful exploitation could fully compromise both the vulnerable DSU application and the underlying operating system.
The other four flaws offer different routes to compromise: CVE-2026-86361 and CVE-2026-86362, both rated 8.2, could let low-privileged local attackers escalate privileges, potentially opening the door to other malicious activity.
CVE-2026-63697, rated 7.6, could allow a high-privileged remote attacker to execute code through improper certificate validation. Lastly, CVE-2026-71168, rated 7.3, is another Path Traversal flaw that could enable code execution by a low-privileged local attacker.
Why these vulnerabilities matter
Dell System Update is designed to install BIOS, firmware, drivers, and other system-level updates, giving it access to highly privileged parts of the server.
That makes vulnerabilities in DSU particularly serious. If an attacker exploits the utility to gain root privileges, they could potentially modify files, change system configurations, install additional tools, or interfere with security controls.
Those actions are not unique to DSU, but root access gives an attacker broad control over the underlying operating system. MITRE ATT&CK groups techniques such as disabling or modifying security tools under its Defense Impairment category.
The path traversal flaws add another layer of risk because they can allow attackers to access files or directories outside their intended locations.
To put that weakness in broader context, BleepingComputer reports that even the Cybersecurity & Infrastructure Security Agency (CISA) has warned that path traversal vulnerabilities “have been called 'unforgivable' since at least 2007.”
What enterprises should do
Organizations running Dell System Update should first identify every affected installation and upgrade DSU to version 2.3.0.0 or later, which Dell lists as the fixed version.
Given the remote, unauthenticated attack path and potential root-level impact, organizations should prioritize the update rather than defer it to a later maintenance cycle.
Teams should also review logs and system activity around affected servers for signs of unexpected DSU activity, privilege escalation, or unexplained changes made through the update mechanism.
A successful compromise could give an attacker enough authority to alter files or security tooling, so organizations should not assume that installing the patch automatically means a previously compromised server is clean.
Finally, enterprises should reduce unnecessary exposure around privileged management software. IT teams can do this by restricting who can run administrative update tools, limiting remote access, maintaining independent security monitoring, and regularly auditing privileged software.
Other news: Cybersecurity Awareness Month highlights four habits worth adopting in 2026: installing security updates faster, using MFA without overestimating it, questioning even legitimate-looking requests, and assuming some personal data may already be exposed.





