The tool you use to push BIOS and firmware updates to Dell PowerEdge servers needs an update of its own. Dell says a critical flaw in Dell System Update (DSU) can let an unauthenticated remote attacker run code as root. The fix is DSU 2.3.0.0. Dell’s advisory went out October 1, and Dell has not reported exploitation.
The tool that patches your servers is the one that needs patching.
What happened
Dell published DSA-2026-324 on October 1, 2026, covering five vulnerabilities in Dell System Update, the command-line tool admins use to deploy BIOS, firmware and software updates on Linux and Windows PowerEdge servers. The headline bug, CVE-2026-86360, is a path traversal rated CVSS 9.6. Dell says an unauthenticated attacker with remote access could use it to execute arbitrary code with root privileges and fully compromise the application and the operating system underneath. Dell’s vector string lists user interaction as required. The advisory does not say what that interaction is.
Don’t Miss the Policy Changes That Affect Security Decisions
Get the key CISA actions, new regulations, guidance, and risk shifts in a quick daily brief.
By subscribing you agree to our Privacy Policy.
Free. Weekday mornings. 5 minutes or less.
The same advisory fixes four high-severity issues. As reported by BleepingComputer, two can lead to remote code execution (CVE-2026-63697 and CVE-2026-71168) and two to privilege escalation (CVE-2026-86361 and CVE-2026-86362). Every DSU release before 2.3.0.0 is affected. Dell lists no workaround and recommends upgrading at the earliest opportunity.
Why it matters
DSU runs with the highest privileges on the servers it touches, and it is often baked into golden images and run by automation. A root-level bug in that path reaches the whole fleet. Nothing is reported exploited yet, so this is a scheduled fix, not a fire drill. Do it before the next firmware cycle runs the old binary everywhere.
What to do first
- Find every host with DSU installed, including build images, jump boxes and configuration-management roles that install it.
- Upgrade to DSU 2.3.0.0 or later. Dell’s download is driver ID J9TK1.
- Update the DSU version pinned in your automation and templates so a rebuild does not bring back the old one.
- Until you upgrade, point DSU only at Dell’s repository or your own mirror, over networks you trust. That is basic hygiene, not a fix: Dell lists no workaround.
Forward this
If you own the Dell server fleet or its build images: update Dell System Update to 2.3.0.0 and change the version pinned in automation. It is not reported exploited, but the top bug runs as root.
Details
- Advisory: DSA-2026-324, initial release 2026-10-01.
- CVE-2026-86360: path traversal; unauthenticated remote attacker; root code execution. CVSS 3.1 9.6 (AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).
- Also fixed: CVE-2026-63697 and CVE-2026-71168 (remote code execution), CVE-2026-86361 and CVE-2026-86362 (privilege escalation), per BleepingComputer’s reading of the advisory.
- Affected: Dell System Update before 2.3.0.0. Fixed: 2.3.0.0 or later (driver ID J9TK1).
- Exploitation: Dell has not flagged any of these as exploited. Not in CISA’s KEV catalog as of October 5, 2026.
- Not the same as: Dell Container Storage Modules (CSM) 1.18.0, covered in Monday’s brief.
Hunt / verify
- Query installed packages across Linux and Windows hosts for DSU and record the version.
- Check that the repository URLs in DSU jobs point to Dell or to your own mirror, not to an address someone added later.
- After the upgrade, run one DSU job and confirm 2.3.0.0 in the job output.
Slack paste: Dell System Update (DSU) before 2.3.0.0: critical path traversal can give an unauthenticated remote attacker root (CVE-2026-86360, 9.6), plus four highs. Upgrade to 2.3.0.0 (driver J9TK1) and update the version pinned in automation. Not reported exploited.
Sources
- https://www.dell.com/support/kbdoc/en-an/000515843/dsa-2026-324-security-update-for-dell-system-update-dsu-vulnerabilities
- https://www.bleepingcomputer.com/news/security/new-dell-system-update-flaw-lets-hackers-gain-root-privileges/
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
By subscribing you agree to our Privacy Policy.
Free. Weekdays. Built for operators.