Dell said it has fixed five security flaws in Dell System Update (DSU), a tool for installing updates. One is rated critical. Dell says an attacker with remote access and no login could potentially reach the file system and run code as root, the top level of control. The bug is a path traversal flaw, which lets an attacker reach files outside the folder a program should stay in. BleepingComputer reported that Dell issued the advisory on Thursday and tracks this flaw as CVE-2026-86360. Dell says versions before 2.3.0.0 are affected and urges customers to upgrade soon.
BleepingComputer reported that the four other flaws are rated high. Two could allow remote code execution (CVE-2026-63697 and CVE-2026-71168). Two could allow privilege escalation (CVE-2026-86361 and CVE-2026-86362). Dell's advisory says three of the five need an attacker who already has local access. According to BleepingComputer, Dell has not marked any of them as exploited in attacks so far. How many systems run the affected versions is not stated.
BleepingComputer says DSU lets IT teams push BIOS, firmware and software updates to Linux and Windows systems on PowerEdge servers. Anyone who runs it has a clear fix: version 2.3.0.0 or later. BleepingComputer also notes that state-backed hacking groups have abused other Dell flaws in recent years. No such use is reported for these.