Dell's 1 October advisory DSA-2026-324 covers five flaws in Dell System Update, the command-line tool used to push BIOS, firmware and driver updates to PowerEdge servers. The critical one is CVE-2026-86360, a path traversal Dell scores at 9.6. Dell has not reported active exploitation.
What happened
Dell says an unauthenticated attacker with remote access can gain filesystem access and can use the bug to run arbitrary code with root privileges. Successful exploitation may fully compromise the application and the operating system under it. The vector includes user interaction (UI:R). There is no workaround.
Every DSU version before 2.3.0.0 is affected. The fix is 2.3.0.0 or later. Dell lists 2.3.0.0 as the remediated line; a later 2.3.0.1 build is also on the driver site. The advisory itself was published on 1 October, after the fixed package had already been posted.
The same bulletin fixes four more high-severity issues: CVE-2026-86361 and CVE-2026-86362 (local privilege escalation, 8.2), plus CVE-2026-63697 (7.6) and CVE-2026-71168 (7.3).
Who is affected
- Linux and Windows hosts running Dell System Update before 2.3.0.0.
- PowerEdge estates where DSU is reachable beyond the management network.
- Teams that also run Dell Container Storage Modules should check that separate max-severity bulletin, not this one.
What to do now
Upgrade Dell System Update to 2.3.0.0 or later on every PowerEdge update host, and keep DSU off the public internet.
Confirm the installed version before you assume a July download already covered you. Dell's score is 9.6, not the 9.8 figure some write-ups used.
Source: BleepingComputer, 5 October 2026, citing Dell DSA-2026-324. New Dell System Update flaw lets hackers gain root privileges.
Also on the blog
- Denmark CPR breach exposes 8.8 million identity records
- CVE-2026-21589 lets attackers read files in 8 Atlassian products
- CVE-2026-63277: LibreOffice spreadsheet runs code with no macro warning
- ASOS push alerts claim a Snowflake compromise
Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.