Dell
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Dell product.
RSS Feeds for Dell security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Dell products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Dell Sorted by Most Security Vulnerabilities since 2018
Known Exploited Dell Vulnerabilities
The following Dell vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.
| Title | Description | Added |
|---|---|---|
| Dell RecoverPoint for Virtual Machines (RP4VMs) Use of Hard-coded Credentials Vulnerability |
Dell RecoverPoint for Virtual Machines (RP4VMs) contains an use of hard-coded credentials vulnerability that could allow an unauthenticated remote attacker to gain unauthorized access to the underlying operating system and root-level persistence. CVE-2026-22769 Exploit Probability: 13.3% |
February 18, 2026 |
| Dell dbutil Driver Insufficient Access Control Vulnerability |
Dell dbutil driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial-of-service, or information disclosure. CVE-2021-21551 Exploit Probability: 79.2% |
March 31, 2022 |
The vulnerability CVE-2021-21551: Dell dbutil Driver Insufficient Access Control Vulnerability is in the top 1% of the currently known exploitable vulnerabilities. The vulnerability CVE-2026-22769: Dell RecoverPoint for Virtual Machines (RP4VMs) Use of Hard-coded Credentials Vulnerability is in the top 5% of the currently known exploitable vulnerabilities.
By the Year
In 2026 there have been 495 vulnerabilities in Dell with an average score of 6.6 out of ten. Last year, in 2025 Dell had 204 security vulnerabilities published. That is, 291 more vulnerabilities have already been reported in 2026 as compared to last year. Last year, the average CVE base score was greater by 0.19
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 495 | 6.58 |
| 2025 | 204 | 6.77 |
| 2024 | 219 | 7.07 |
| 2023 | 168 | 6.97 |
| 2022 | 129 | 7.20 |
| 2021 | 139 | 6.94 |
| 2020 | 35 | 7.45 |
| 2019 | 54 | 7.32 |
| 2018 | 57 | 7.21 |
It may take a day or so for new Dell vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Dell Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-76114 | Sep 29, 2026 |
Cleartext Transmission Vulnerability in Dell SCG Policy Manager v<5.34.00.16Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Cleartext Transmission of Sensitive Information vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure. |
|
| CVE-2026-73599 | Sep 29, 2026 |
Dell SCG <5.34.00.16 - Open Redirect (URL Red.) SSRF VulnerabilityDell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an URL Redirection to Untrusted Site ('Open Redirect') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Server-side request forgery. |
|
| CVE-2026-73598 | Sep 29, 2026 |
Dell SCG Policy Manager <=5.34.00.16 - Incorrect Permission Assignment EoPDell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. |
|
| CVE-2026-73597 | Sep 29, 2026 |
Dell SCG Policy Manager <5.34.00.16 CSRF VulnerabilityDell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Cross-Site Request Forgery (CSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure, Information tampering, Launch of phishing attacks, and Protection mechanism bypass. |
|
| CVE-2026-73596 | Sep 29, 2026 |
Dell SCG Policy Manager <5.34 Insecure Init Allows ElevationDell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Initialization of a Resource with an Insecure Default vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges, Information tampering, Protection mechanism bypass, and Unauthorized access. |
|
| CVE-2026-73595 | Sep 29, 2026 |
Dell SCG Policy Manager <5.36: Code Exec via Download of Code W/O Integrity CheckDell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, Versions prior to 5.36, contains a Download of Code Without Integrity Check vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Code execution, Information disclosure, Information tampering, and Protection mechanism bypass. |
|
| CVE-2026-73594 | Sep 29, 2026 |
Dell Secure Connect Gateway Policy Manager <5.34 Improper Certificate ValidationDell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, Versions prior to 5.36, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information disclosure, Information tampering, and Protection mechanism bypass. |
|
| CVE-2026-73593 | Sep 29, 2026 |
Dell SCG Policy Manager (<5.34.00.16) Active Debug Code Info DisclosureDell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Active Debug Code vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure, Information tampering, Protection mechanism bypass, and Unauthorized access. |
|
| CVE-2026-70413 | Sep 28, 2026 |
Dell Live Optics Collector <27.2.13.310: Hardcoded PW RCE, Info ExposureDell Live Optics Collector, versions prior to 27.2.13.310, contain(s) a Use of Hard-coded Password vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure. |
|
| CVE-2026-80359 | Sep 28, 2026 |
Dell BOSS 17G N1: OTDI Improper Access Control (before 2.2.13.2038)Dell Boot Optimized Server Storage (BOSS), versions prior to 2.2.13.2038, contains an On-Chip Debug and Test Interface With Improper Access Control vulnerability in the SMCU on 17G BOSS-N1 controllers. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Unauthorized access. |
|
| CVE-2026-80358 | Sep 28, 2026 |
Physical Access via ODBC on Dell BOSS SMCU (pre-2.2.13.2038)Dell Boot Optimized Server Storage (BOSS), versions prior to 2.2.13.2038, contains an On-Chip Debug and Test Interface With Improper Access Control vulnerability in the SMCU on 17G BOSS-N1 controllers. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Unauthorized access. |
|
| CVE-2026-80357 | Sep 28, 2026 |
Dell BOSS SMCU OBDT Improper Access Control (pre-2.2.13.2038)Dell Boot Optimized Server Storage (BOSS), versions prior to 2.2.13.2038, contains an On-Chip Debug and Test Interface With Improper Access Control vulnerability in the SMCU on 17G BOSS-N1 controllers. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Unauthorized access. |
|
| CVE-2026-82164 | Sep 24, 2026 |
Dell Trusted Device Client IECRA before 8.1.359.0Dell Trusted Device Client, versions prior to 8.1.359.0, contain an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information tampering. |
|
| CVE-2026-56792 | Sep 24, 2026 |
Dell RCC <5.2.206 Improper Auth Exposes Low-Privileged AoPDell Rugged Control Center (RCC), versions prior to 5.2.206, contain an Improper Authorization vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges. |
|
| CVE-2026-81473 | Sep 24, 2026 |
Dell RCC Improper Auth EoP before 5.2.206Dell Rugged Control Center (RCC), versions prior to 5.2.206, contain an Improper Authorization vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges. |
|
| CVE-2026-81455 | Sep 24, 2026 |
Dell ThinOS 10 <1.3 Missing Auth for Critical Function (CVE-2026-81455)Dell ThinOS 10, versions prior to SecurityAddon_2605.10.2766_T10, contain a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. |
|
| CVE-2026-82157 | Sep 24, 2026 |
Dell ThinOS 10 Improper Cert Validation (pre-2605.10.2766_T10)Dell ThinOS 10, versions prior to SecurityAddon_2605.10.2766_T10, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Protection mechanism bypass and Unauthorized access. |
|
| CVE-2026-73591 | Sep 23, 2026 |
Dell Secure Connect Gateway (<=5.34.00.15) Sensitive Info LeakDell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Inclusion of Sensitive Information in Source Code vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information exposure. |
|
| CVE-2026-73589 | Sep 23, 2026 |
Dell SCG Policy Manager <5.36 Weak Encoding Password VulnerabilityDell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, Versions prior to 5.36, contains a Weak Encoding for Password vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure, Information tampering, Protection mechanism bypass, and Unauthorized access. |
|
| CVE-2026-73588 | Sep 23, 2026 |
Dell SCG Policy Manager <5.34.00.16: Missing Auth for Critical FunctionDell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. |
|
| CVE-2026-73587 | Sep 23, 2026 |
Dell SCG Policy Manager <5.34.00.16 Improper Cert Validation VulnerabilityDell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information disclosure, Information tampering, and Protection mechanism bypass. |
|
| CVE-2026-73586 | Sep 23, 2026 |
Dell SCG Policy Manager <5.34.00.16 Insufficient Session Expiration EOPDell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Insufficient Session Expiration vulnerability. A low privileged attacker with adjacent network access could potentially exploit this vulnerability, leading to Elevation of privileges, Protection mechanism bypass, and Unauthorized access. |
|
| CVE-2026-71178 | Sep 23, 2026 |
Dell SCG Policy Manager <5.34.00.16: Non-Canonical URL Path Auth BypassDell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Use of Non-Canonical URL Paths for Authorization Decisions vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. |
|
| CVE-2026-71177 | Sep 23, 2026 |
Dell SCG Policy Manager <=5.34.00.16: Improper UI Layer Restriction (CVE202671177)Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Restriction of Rendered UI Layers or Frames vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges and Session theft. |
|
| CVE-2026-61413 | Sep 23, 2026 |
Dell SCG Policy Manager <5.34.00.16 Improper Privilege Management VulnerabilityDell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Privilege Management vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. |
|
| CVE-2026-49811 | Sep 21, 2026 |
Dell Command Monitor <10.13.2: Incorrect Permission Assignment (EoP)Dell Command | Monitor (DCM), versions prior to 10.13.2, contain an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges. |
|
| CVE-2026-81469 | Sep 21, 2026 |
Dell Inventory Collector Client pre-15.0.0 Unquoted Search Path CVE-2026-81469Dell Inventory Collector Client, versions prior to 15.0.0, contain an Unquoted Search Path or Element vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution and Elevation of Privileges |
|
| CVE-2026-82165 | Sep 21, 2026 |
Dell Command Integr Suite <=6.7.1 Incorrect Default Perms (Low Priv Local)Dell Command | Integration Suite for System Center, versions prior to 6.7.2, contain an Incorrect Default Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information Disclosure. |
|
| CVE-2026-49810 | Sep 21, 2026 |
Dell Command Powershell Provider <2.10.2: Log Injection Info DisclosureDell Command Powershell Provider (DCPP), versions prior to 2.10.2 contain an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information Disclosure. |
|
| CVE-2026-82163 | Sep 21, 2026 |
Dell Command | Intel vPro OOB Incorrect Default Permissions (4.7.1)Dell Command | Intel vPro Out of Band, versions prior to 4.7.2, contain an Incorrect Default Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information Disclosure. |
|
| CVE-2026-56795 | Sep 17, 2026 |
Dell Server Update Utility <26.07.01: Unctrl Search Path Element local code execDell Server Update Utility, versions prior to 26.07.01, contains an Uncontrolled Search Path Element vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution. |
|
| CVE-2026-26950 | Sep 17, 2026 |
Dell SmartFabric Manager 2.2.1 - Insufficient Data Auth (CVE-2026-26950)Dell SmartFabric Manager, versions prior to 2.2.1, contains an Insufficient Verification of Data Authenticity vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. |
|
| CVE-2026-54471 | Sep 17, 2026 |
Dell SmartFabric Manager <2.2.1 Improper Privilege Handling VulnerabilityDell SmartFabric Manager, versions prior to 2.2.1, contains an Improper Handling of Insufficient Permissions or Privileges vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure. |
|
| CVE-2026-81447 | Sep 17, 2026 |
Dell OM SA Improper Cert Validation before 11.1.0.3Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information disclosure and Information tampering. |
|
| CVE-2026-80356 | Sep 17, 2026 |
Dell OMSA <11.1.0.3 Sensitive Info Exposure to Unauth ActorsDell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Exposure of Sensitive Information to an Unauthorized Actor vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure. |
|
| CVE-2026-81446 | Sep 17, 2026 |
Dell OpenManage Server Administrator <11.1.0.3 SSRF VulnerabilityDell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Server-Side Request Forgery (SSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Server-side request forgery. |
|
| CVE-2026-81445 | Sep 17, 2026 |
Dell OMGA Improper Privilege Mgmt: Priv Escalation (v<11.1.0.3)Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Privilege Management vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. |
|
| CVE-2026-81453 | Sep 17, 2026 |
Dell OpenManage Server Administrator <11.1.0.3 Path Traversal VulnerabilityDell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access for attacker. |
|
| CVE-2026-81443 | Sep 17, 2026 |
Dell OpenManage Server Admin SSRF before 11.1.0.3Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Server-Side Request Forgery (SSRF) vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Server-side request forgery. |
|
| CVE-2026-81442 | Sep 17, 2026 |
Dell OpenManage Server Admin <11.1.0.3 Privilege Escalation CVE-2026-81442Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Privilege Management vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information tampering and Unauthorized access. |
|
| CVE-2026-80355 | Sep 17, 2026 |
Dell OpenManage Server Administrator <11.1.0.3 CSRF Remote ExecDell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Cross-Site Request Forgery (CSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution. |
|
| CVE-2026-81481 | Sep 17, 2026 |
Dell OpenManage Server Administrator <11.1.0.3 Path Traversal VulnerabilityDell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access for attacker. |
|
| CVE-2026-81480 | Sep 17, 2026 |
Dell OpenManage Server Administrator <11.1.0.3 Stack Buffer OverflowDell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Stack-based Buffer Overflow vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution. |
|
| CVE-2026-81441 | Sep 17, 2026 |
Missing Auth in Dell OpenManage SM Admin <11.1.0.3Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Denial of service. |
|
| CVE-2026-81440 | Sep 17, 2026 |
Dell OpenManage Server Admin: Hardcoded Credentials (CVE202681440) <11.1.0.3Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Use of Hard-coded Credentials vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. |
|
| CVE-2026-81479 | Sep 17, 2026 |
Dell OM Server Admin <11.1.0.3: Partial Str Comp leading to DoS (LPA)Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Partial String Comparison vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Denial of service. |
|
| CVE-2026-81478 | Sep 17, 2026 |
Dell OMA Vulnerable Pre-11.1.0.3 Hard-coded Crypto Key (Unauthorized Access)Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Use of Hard-coded Cryptographic Key vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. |
|
| CVE-2026-81477 | Sep 17, 2026 |
Dell OpenManage SA <=11.1.0.3 Remote HeapBFO for Code ExecDell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Heap-based Buffer Overflow vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution. |
|
| CVE-2026-81476 | Sep 17, 2026 |
OS Command Injection in Dell OpenManage SA <11.1.0.3Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution. |
|
| CVE-2026-81475 | Sep 17, 2026 |
Dell OpenManage Server Administrator <11.1.0.3: Missing Auth Remote ExecDell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution. |