Vulnerabilities · 7h ago
Dell disclosed a critical privilege-escalation flaw in its System Update (DSU) command-line interface and told customers to patch immediately. The bug sits in a trusted deployment utility, so a tool meant to manage updates can instead hand an attacker root on the machine that runs it.
In plain terms, if an attacker or untrusted automation can invoke DSU under a limited account, the flaw can let that process escape into full administrator control. That matters most on Linux admin workstations and managed servers, where deployment tooling is often assumed to be safe because it only runs during maintenance.
The exposure is in the management path itself: systems that rely on DSU for fleet updates inherit the risk whenever that tool can be reached, even if the rest of the machine is otherwise locked down. Dell has not tied the disclosure to exploitation or a fixed remediation version, so the immediate issue is trust in the update channel, not a wider campaign.
3 sources covering this story
Rilevate vulnerabilità in Dell System Update
Aggiornamenti di sicurezza Dell Technologies sanano 5 vulnerabilità, di cui una con gravità "critica" e 4 con gravità "alta", in Dell System Update, software per la gestione degli aggiornamenti per driver, BIOS, firmware e applicazioni.
Dell urges users to patch CVE-2026-86360, a Dell System Update vulnerability that could let unauthenticated remote attackers run code as root.
New Dell System Update flaw lets hackers gain root privileges
Dell warned customers to patch a critical vulnerability in the System Update (DSU) command-line interface (CLI) deployment tool as soon as possible.
Part of the PlainSec briefing for 2026-10-06