Dell has alerted users that a critical flaw in its Dell System Update (DSU) tool could let an attacker gain root access to a victim’s machine, potentially giving them complete compromise of the vulnerable application and underlying operating system. The company has urged affected customers to update as soon as possible.
The vulnerability is tracked as CVE-2026-86360 and has a CVSS score of 9.6, placing it within the “Critical” category. The flaw affects unpatched versions of the tool and could allow an unauthenticated threat actor to remotely access a machine’s file system and “execute arbitrary code with root privileges,” though Dell’s scoring indicates some user interaction is required. The company has not said the flaw is being exploited.
As Dell noted in an advisory published on Oct. 1, versions of the DSU tool prior to 2.3.0.0 contained an Improper Limitation of a Pathname to a Restricted Directory flaw, otherwise known as Path Traversal. If successfully exploited, this “may allow complete compromise of the vulnerable application and underlying operating system,” Dell warned.
The company has advised users to upgrade as soon as they can. The patched version of the DSU app can be downloaded from Dell’s website.
Four More DSU Flaws Fixed in the Same Update
This vulnerability is not the only one that Dell cautioned about in its advisory note. Alongside the 9.6-rated CVE-2026-86360 can be found CVE-2026-86361, which has a CVSS score of 8.2 and involves an Incorrect Permission Assignment for Critical Resource flaw that permits a low-privileged attacker to gain local access and potentially elevate their privileges.
Dell also outlined three other weaknesses in the DSU tool, ranging in severity from 7.3 to 8.2 on the CVSS scale. These flaws utilize privilege escalation and RCE that could be harnessed by threat actors with varying levels of system privilege and involve both local and remote access.
Dell advises all organizations running the DSU tool to upgrade to version 2.3.0.0 or as soon as possible.