Critical Path‑Traversal in Dell System Update (CVE‑2026‑86360) Allows Remote Root Code Execution
Dell System Update versions before 2.3.0.0 contain a critical path‑traversal vulnerability (CVE‑2026‑86360) that lets an unauthenticated attacker execute code as root. The flaw underscores the importance of continuous patch‑management evidence for audit readiness.
ADTP Breach Watch· October 6, 2026· Help Net Security
The DSU tool permits drivers, BIOS, and firmware updates on PowerEdge servers. CVE‑2026‑86360 lets an unauthenticated remote attacker traverse directories, write files, and run arbitrary code with root privileges, potentially compromising the host OS.
Why it matters for trust and compliance
The issue highlights the control objective of timely vulnerability remediation; maintaining verifiable patch records is essential for a defensible audit trail across frameworks like NIST CSF.
Continuous evidence of patch status supports control‑assurance reporting.
Automated collection of remediation data strengthens audit readiness.
Who is affected
CLOUD_INFRA
Recommended actions
Identify all DSU installations and upgrade to version 2.3.0.0 or later.
Ingest patch‑status data into your control‑mapping platform for continuous monitoring.
Restrict network access to DSU management interfaces.
Details
CVEs
CVE-2026-86360
Get the Breach Digest
The incidents that matter for your vendors and your data, analysed for practitioners, in one email.