Dell’s server update tool needs its own update — move DSU to 2.3.0.0

By George Bailey   Published: 10/06/26   4 min read

The tool you use to push BIOS and firmware updates to Dell PowerEdge servers needs an update of its own. Dell says a critical flaw in Dell System Update (DSU) can let an unauthenticated remote attacker run code as root. The fix is DSU 2.3.0.0. Dell’s advisory went out October 1, and Dell has not reported exploitation.

The tool that patches your servers is the one that needs patching.

What happened

Dell published DSA-2026-324 on October 1, 2026, covering five vulnerabilities in Dell System Update, the command-line tool admins use to deploy BIOS, firmware and software updates on Linux and Windows PowerEdge servers. The headline bug, CVE-2026-86360, is a path traversal rated CVSS 9.6. Dell says an unauthenticated attacker with remote access could use it to execute arbitrary code with root privileges and fully compromise the application and the operating system underneath. Dell’s vector string lists user interaction as required. The advisory does not say what that interaction is.

The same advisory fixes four high-severity issues. As reported by BleepingComputer, two can lead to remote code execution (CVE-2026-63697 and CVE-2026-71168) and two to privilege escalation (CVE-2026-86361 and CVE-2026-86362). Every DSU release before 2.3.0.0 is affected. Dell lists no workaround and recommends upgrading at the earliest opportunity.

Why it matters

DSU runs with the highest privileges on the servers it touches, and it is often baked into golden images and run by automation. A root-level bug in that path reaches the whole fleet. Nothing is reported exploited yet, so this is a scheduled fix, not a fire drill. Do it before the next firmware cycle runs the old binary everywhere.

What to do first

Forward this

If you own the Dell server fleet or its build images: update Dell System Update to 2.3.0.0 and change the version pinned in automation. It is not reported exploited, but the top bug runs as root.

Details

Hunt / verify

Slack paste: Dell System Update (DSU) before 2.3.0.0: critical path traversal can give an unauthenticated remote attacker root (CVE-2026-86360, 9.6), plus four highs. Upgrade to 2.3.0.0 (driver J9TK1) and update the version pinned in automation. Not reported exploited.

Sources

George Bailey

George Bailey is a cybersecurity researcher and writer at CyberExperts, covering cyber threats, AI, cloud security, vulnerabilities, and defensive strategies. His goal is to help security professionals quickly understand what matters most and how it impacts their organizations.