Close Menu
NCIJ Network NCIJ Network
    What's Hot

    OpenAI PR tells journalist to ‘move on’ while asking Sam Altman about a ChatGPT user’s suicide

    October 6, 2026

    South Korea probes bank breaches amid suspected AI-powered attacks

    October 6, 2026

    Coinbase Business Chief: Big Banks Increasing BTC Exposure

    October 6, 2026
    Facebook X (Twitter) Instagram
    Trending
    • OpenAI PR tells journalist to ‘move on’ while asking Sam Altman about a ChatGPT user’s suicide
    • South Korea probes bank breaches amid suspected AI-powered attacks
    • Coinbase Business Chief: Big Banks Increasing BTC Exposure
    • A Journey to the Depths of Ancient Mars?
    • Spain’s Sánchez Calls Snap Elections Over Failed Housing Reform
    • Did Trump say he feels badly for ‘Cornell 7’ because they ‘won’t get a fair shake’?
    • Trump says taxpayers will no longer fund TV ads that praise him | Donald Trump News
    • The Matic is the first robovac to get an FCC ban waiver, not that it needs it
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, October 6
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    New Dell System Update flaw lets hackers gain root privileges

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKOctober 6, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Dell warned customers to patch a critical vulnerability in the System Update (DSU) command-line interface (CLI) deployment tool as soon as possible.

    DSU lets enterprise IT administrators deploy BIOS, firmware, and software updates onto Linux and Windows systems on PowerEdge enterprise server infrastructure.

    In a Thursday security advisory, the company said the flaw (tracked as CVE-2026-86360) allows threat actors to execute code with root privileges on unpatched devices by exploiting a path traversal weakness.

    “An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access for [an] attacker,” the company Dell said. “This vulnerability is considered critical because it can be leveraged by an unauthenticated attacker to execute arbitrary code with root privileges. Successful exploitation may allow complete compromise of the vulnerable application and underlying operating system.”

    The FBI and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) have urged software companies since May 2024 to remove path traversal weaknesses from their products before shipping, saying such security issues “have been called ‘unforgivable’ since at least 2007.”

    Dell also patched four high-severity Dell System Update security flaws on Thursday, two that remote attackers can exploit to gain remote code execution (CVE-2026-63697 and CVE-2026-71168) and two more that can be abused for privilege escalation (CVE-2026-86361 and CVE-2026-86362).

    “Dell recommends customers upgrade at the earliest opportunity,” the company said, advising customers to update Dell System Update (DSU) to 2.3.0.0 or later, which patches the flaws.

    That same day, Dell also urged IT administrators to patch two maximum-severity Container Storage Modules (CSM) vulnerabilities (CVE-2026-63688 and CVE-2026-63692) as soon as possible.

    While Dell has not yet flagged any of these flaws as actively exploited, state-backed hacking groups have abused other Dell vulnerabilities in attacks in recent years.

    For instance, the North Korean Lazarus hacking group deployed a Windows rootkit on victims’ systems by exploiting an insufficient access control vulnerability (CVE-2021-21551) in the Dell dbutil driver.

    More recently, Mandiant and the Google Threat Intelligence Group (GTIG) revealed in February that suspected Chinese cyber spies (tracked as UNC6201) had been exploiting a hardcoded-credential vulnerability (CVE-2026-22769) in Dell RecoverPoint for Virtual Machines since at least mid-2024 to create hidden network interfaces on VMware ESXi servers and deploy malware payloads.

    They also found overlaps between UNC6201 and the Silk Typhoon Chinese cyberespionage group, which is known for targeting government agencies with custom Zipline and Spawnant malware in Ivanti zero-day attacks.

    Days later, CISA ordered federal agencies to patch vulnerable Dell systems on their networks within three days.


    article image

    Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

    Save your seat

    Dell Flaw gain hackers lets privileges Root System update
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    South Korea probes bank breaches amid suspected AI-powered attacks

    Tories pledge new ‘Britannia Shield’ UK air defence system

    Denmark population registry data breach affects 8.8 million people

    The Credential Layer Is Expanding Faster Than Security Teams Can See It

    OpenAI is adding invisible watermarks to ChatGPT and Codex text in the EU

    Rejetto HFS servers now actively scanned for critical RCE flaw

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    OpenAI PR tells journalist to ‘move on’ while asking Sam Altman about a ChatGPT user’s suicide

    October 6, 2026

    South Korea probes bank breaches amid suspected AI-powered attacks

    October 6, 2026

    Coinbase Business Chief: Big Banks Increasing BTC Exposure

    October 6, 2026

    A Journey to the Depths of Ancient Mars?

    October 6, 2026
    Latest Posts

    What do cybersecurity leaders want in staff? These 3 skills beat certifications and experience

    August 9, 2026

    Britain is paying the price for failing to invest in its young people | Richard Partington

    August 9, 2026

    A Democratic Socialist Spreads the Word, Even in Hostile Territory

    August 9, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    OpenAI PR tells journalist to ‘move on’ while asking Sam Altman about a ChatGPT user’s suicide

    October 6, 2026

    South Korea probes bank breaches amid suspected AI-powered attacks

    October 6, 2026

    Coinbase Business Chief: Big Banks Increasing BTC Exposure

    October 6, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.