Dell is telling customers to upgrade Dell System Update after a path-traversal bug that can hand an unauthenticated remote attacker root on the host. CVE-2026-86360 scores 9.6. Advisory DSA-2026-324 covers five flaws. Dell has not reported exploitation.
What happened
DSU is the command-line tool admins use to push BIOS, firmware, and driver updates to PowerEdge servers. It runs with the rights those updates need. A flaw in it is a flaw in the update path, not in a spare utility.
Dell describes CVE-2026-86360 as improper limitation of a pathname. An unauthenticated attacker with remote access could reach the filesystem and run code as root, with full compromise of the app and the operating system. The published vector includes user interaction, so this is not a silent internet worm on every DSU install. It is still a critical bug on a privileged tool.
The fixed package, 2.3.0.0, has been available since late July 2026. The public bulletin is dated 1 October. Shops that did not move when the package landed are the ones exposed now.
Who is affected
Every DSU install before 2.3.0.0, on the Linux and Windows hosts used to update PowerEdge fleets.
- CVE-2026-86360, CVSS 9.6, unauthenticated path traversal to root code execution
- CVE-2026-63697 and CVE-2026-71168, remote execution
- CVE-2026-86361 and CVE-2026-86362, local privilege escalation
What to do now
Upgrade every DSU install to 2.3.0.0 or later. There is no workaround. Check jump hosts and automation accounts that run DSU, not only the servers being patched. Dell also shipped separate maximum-severity fixes for Container Storage Modules; that is a different advisory and should not be confused with this one.
Source: Help Net Security, 6 October 2026. Dell advisory: DSA-2026-324.
Also on the blog
- NetScaler CVE-2026-88779 (CVSS 8.7) crashes SAML appliances
- FortiMail CVE-2026-104286 (CVSS 9.8) file-write zero-day
- Exchange CVE-2026-96940: signed-in users can read other mailboxes
- Atlassian CVE-2026-21589 (CVSS 9.3) file read on 8 products
Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.