Dell DSU CVE-2026-86360 (CVSS 9.6) root on PowerEdge updates
Dell System Update path traversal before 2.3.0.0

Dell DSU CVE-2026-86360 (CVSS 9.6) root on PowerEdge updates

Dell is telling customers to upgrade Dell System Update after a path-traversal bug that can hand an unauthenticated remote attacker root on the host. CVE-2026-86360 scores 9.6. Advisory DSA-2026-324 covers five flaws. Dell has not reported exploitation.

What happened

DSU is the command-line tool admins use to push BIOS, firmware, and driver updates to PowerEdge servers. It runs with the rights those updates need. A flaw in it is a flaw in the update path, not in a spare utility.

Dell describes CVE-2026-86360 as improper limitation of a pathname. An unauthenticated attacker with remote access could reach the filesystem and run code as root, with full compromise of the app and the operating system. The published vector includes user interaction, so this is not a silent internet worm on every DSU install. It is still a critical bug on a privileged tool.

The fixed package, 2.3.0.0, has been available since late July 2026. The public bulletin is dated 1 October. Shops that did not move when the package landed are the ones exposed now.

Who is affected

Every DSU install before 2.3.0.0, on the Linux and Windows hosts used to update PowerEdge fleets.

What to do now

Upgrade every DSU install to 2.3.0.0 or later. There is no workaround. Check jump hosts and automation accounts that run DSU, not only the servers being patched. Dell also shipped separate maximum-severity fixes for Container Storage Modules; that is a different advisory and should not be confused with this one.

Source: Help Net Security, 6 October 2026. Dell advisory: DSA-2026-324.

Also on the blog

Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.

Atlassian CVE-2026-21589 (CVSS 9.3) file read on 8 products
Unauthenticated arbitrary file access on Data Center