Dell
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Dell product.
RSS Feeds for Dell security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Dell products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Dell Sorted by Most Security Vulnerabilities since 2018
Known Exploited Dell Vulnerabilities
The following Dell vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.
| Title | Description | Added |
|---|---|---|
| Dell RecoverPoint for Virtual Machines (RP4VMs) Use of Hard-coded Credentials Vulnerability |
Dell RecoverPoint for Virtual Machines (RP4VMs) contains an use of hard-coded credentials vulnerability that could allow an unauthenticated remote attacker to gain unauthorized access to the underlying operating system and root-level persistence. CVE-2026-22769 Exploit Probability: 13.1% |
February 18, 2026 |
| Dell dbutil Driver Insufficient Access Control Vulnerability |
Dell dbutil driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial-of-service, or information disclosure. CVE-2021-21551 Exploit Probability: 53.1% |
March 31, 2022 |
2 known exploited Dell vulnerabilities are in the top 5% (95th percentile or greater) of the EPSS exploit probability rankings.
By the Year
In 2026 there have been 249 vulnerabilities in Dell with an average score of 6.6 out of ten. Last year, in 2025 Dell had 204 security vulnerabilities published. That is, 45 more vulnerabilities have already been reported in 2026 as compared to last year. Last year, the average CVE base score was greater by 0.18
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 249 | 6.58 |
| 2025 | 204 | 6.77 |
| 2024 | 219 | 7.07 |
| 2023 | 168 | 6.97 |
| 2022 | 129 | 7.20 |
| 2021 | 139 | 6.94 |
| 2020 | 35 | 7.45 |
| 2019 | 54 | 7.32 |
| 2018 | 57 | 7.21 |
It may take a day or so for new Dell vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Dell Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-59915 | Aug 18, 2026 |
Dell Alienware Command Center 6.14.20.0 Least Priv Violation Priv EscalationDell Alienware Command Center (AWCC), versions prior to 6.14.20.0, contain a Least Privilege Violation vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges. |
|
| CVE-2026-49500 | Aug 18, 2026 |
Alienware Command Center <=6.14.20.0 Improper Link Following VulnerabilityDell Alienware Command Center (AWCC), versions prior to 6.14.20.0, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Denial of Service and Elevation of Privileges. |
|
| CVE-2026-32657 | Aug 18, 2026 |
Dell Systems Symlink Follow PrivEsc (AppSync 4.6.0.0, UCC Edge 3.0.1)Dell AppSync Version 4.6.0.0, Dell Metro Node Version 8.0.0, Dell UCC Edge Version 3.0.1, Dell VxRail Version 8.0.322, Dell PowerMax Version 10.3.0, Dell Unity Version 5.4, Dell PowerFlex Manager Version 4.5.4, Dell PowerFlex Intelligent Catalog Versions 46.377.00 and 46.382.00 and Dell PowerFlex Rack version 4.5.4 and prior versions, contain(s) an UNIX Symbolic Link (Symlink) Following vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. |
|
| CVE-2026-67262 | Aug 18, 2026 |
Dell PowerStore contains a Missing Authorization vulnerabilityDell PowerStore contains a Missing Authorization vulnerability. An attacker with access to a mapped host could exploit this vulnerability to read from or write to LUNs that the host is not authorized to access, bypassing per-initiator LUN access controls and leading to protection mechanism bypass. |
|
| CVE-2026-70415 | Aug 18, 2026 |
Dell PowerStore SDNAS NFS/RPC Buffer Copy Without Size Check RCE/DoSDell PowerStore SDNAS contains a Buffer Copy without Checking Size of Input vulnerability in the NFS/RPC. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Command execution and Denial of service. |
|
| CVE-2026-67271 | Aug 18, 2026 |
Dell PowerStore SDNAS SMB/OOB Write Exploit Enables RCEDell PowerStore SDNAS, contains an Out-of-bounds Write vulnerability in the SMB/CIFS. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Denial of service and Remote execution. This is a Critical vulnerability as a remote user could send a specially crafted SMB packet and cause a crash, that is persistent in case automatic restarts are enabled. Additionally, a more sophisticated attacker could use the same vulnerability for Remote Code execution. |
|
| CVE-2026-61407 | Aug 18, 2026 |
Dell Watchdog Timer Driver <=2.0.0.0 Exposed IOCTL allows PrivEscDell Watchdog Timer Driver versions prior to 2.0.0.1 contain an Exposed IOCTL with Insufficient Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Privilege Escalation. |
|
| CVE-2026-56089 | Aug 17, 2026 |
Dell ObjectScale <=4.3.0.1 Path Traversal (Info Disclosure)Dell ObjectScale, versions prior to 4.3.0.1, contain(s) a Path Traversal vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure. |
|
| CVE-2026-59911 | Aug 17, 2026 |
Dell ObjectScale <4.3.0.1 svc_tools: Sensitive Info Logged - InfoDisclosureDell ObjectScale, versions prior to 4.3.0.1, contain(s) an Insertion of Sensitive Information into Log File vulnerability in the svc_tools. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure. |
|
| CVE-2026-59909 | Aug 17, 2026 |
Dell ObjectScale <4.3.0.1 Path Traversal - Low Privileged Local AccessDell ObjectScale, versions prior to 4.3.0.1, contain(s) a Path Traversal vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information tampering. |
|
| CVE-2026-56090 | Aug 17, 2026 |
Dell ObjectScale <4.3.0.1: UncSearchPathElement LPEDell ObjectScale, versions prior to 4.3.0.1, contain(s) an Uncontrolled Search Path Element vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. |
|
| CVE-2026-56685 | Aug 17, 2026 |
Dell ObjectScale v<4.3.0.1: OS Command Injection via Improper NeutralizationDell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution. |
|
| CVE-2026-59910 | Aug 17, 2026 |
Dell ObjectScale OS Command Injection (pre-4.3.0.1) Priv EscDell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. |
|
| CVE-2026-56686 | Aug 17, 2026 |
Dell ObjectScale <4.3.0.1 OS Command Injection Privilege EscalationDell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. |
|
| CVE-2026-70412 | Aug 17, 2026 |
Dell iDRAC9/10 < 7.20.30.50/1.20.60.50: Remanent Memory Read (Info Disclosure)Dell iDRAC9, versions prior to 7.20.30.50, and Dell iDRAC10, version prior to 1.20.60.50, contain a Remanent Data Readable after Memory Erase vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure. |
|
| CVE-2026-63700 | Aug 14, 2026 |
Dell Wyse Management Suite <=2605.0.2 Incorrect Default PermissionDell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Incorrect Default Permission vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Privilege Escalation. |
|
| CVE-2026-66271 | Aug 14, 2026 |
Dell WMS <2605.0.2: Unrestricted Dangerous File Upload RCEDell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Unrestricted Upload of File with Dangerous Type vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote Code Execution. |
|
| CVE-2026-66270 | Aug 14, 2026 |
Dell Wyse Management Suite <2605.0.2 Unrestricted File Upload RCEDell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Unrestricted Upload of File with Dangerous Type vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote Code Execution. |
|
| CVE-2026-66272 | Aug 14, 2026 |
Missing Auth in Dell Wyse WMS (pre2605.0.2)Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure. |
|
| CVE-2026-63701 | Aug 14, 2026 |
Dell Wyse Management Suite 2605 < 2605.0.2 Improper Deserialization PrivEscDell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Improper Deserialization of Untrusted Data vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Privilege Escalation. |
|
| CVE-2026-63702 | Aug 14, 2026 |
Dell WMS <2605.0.2: Hardcoded Creds VulnerabilityDell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain a Use of Hard-coded Credentials vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access. |
|
| CVE-2026-46731 | Aug 12, 2026 |
Dell DDPM Windows 2.3.0.17 Auth Bypass Spoofing (EOP)Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain an Authentication Bypass by Spoofing vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges and arbitrary code execution. |
|
| CVE-2026-59914 | Aug 12, 2026 |
Auth Bypass in Dell DDPM (<2.3.0.17) allows local elevationDell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain an Authentication Bypass by Spoofing vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges and arbitrary code execution. |
|
| CVE-2026-59917 | Aug 12, 2026 |
Dell DDPM 2.3.0.17 Improper Access Control PrivEsc (DDPM)Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges and arbitrary code execution. |
|
| CVE-2026-59916 | Aug 12, 2026 |
Dell DDPM Improper Access Control Privilege Escalation (pre v2.3.0.17)Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges and arbitrary code execution. |
|
| CVE-2026-56794 | Aug 07, 2026 |
Dell OpenManage Server Administrator <11.1.0.2: Relative Path TraversalDell OpenManage Server Administrator, versions prior to 11.1.0.2, contains a Relative Path Traversal vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access for attacker. |
|
| CVE-2026-56793 | Aug 07, 2026 |
Improper Auth in Dell OpenManage SMA < 11.1.0.2 & Unauthorized AccessDell OpenManage Server Administrator, versions prior to 11.1.0.2, contains an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. |
|
| CVE-2026-54489 | Aug 06, 2026 |
Dell VSI vSphere Client <=10.11.1.0 SI DisclosureDell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) a Sensitive Information Disclosure vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to information disclosure and session hijacking. This vulnerability is considered critical as it allows an unauthenticated attacker to obtain active session credentials and fully impersonate authenticated users, including administrators. Dell recommends customers to upgrade at the earliest opportunity. |
|
| CVE-2026-67261 | Aug 06, 2026 |
Dell VSI vSphere Client <10.11.1.0: OS Command Injection via IAPIDell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) an OS Command Injection vulnerability in the IAPI component. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying operating system with root privileges. Exploitation may lead to a complete system takeover by an attacker. This vulnerability is considered critical as it allows an unauthenticated remote attacker to achieve arbitrary code execution as root, potentially compromising the entire VSI deployment and underlying infrastructure. Dell recommends customers to upgrade at the earliest opportunity. |
|
| CVE-2026-64993 | Aug 06, 2026 |
Dell RVTools <4.8.1 Improper Cert Validation (Collector)Dell RVTools versions prior to 4.8.1, contains an improper certificate validation vulnerability in the collector. A remote unauthenticated attacker could potentially exploit this vulnerability leading to loss of confidentiality and integrity. |
|
| CVE-2026-59913 | Aug 03, 2026 |
Dell DDPM Mac <2.3.0.1005 Missing Auth PrivEsc (LowPriv)Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain a Missing Authentication for Critical Function vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. |
|
| CVE-2026-59912 | Aug 03, 2026 |
Improper Access Control in Dell DDPM Mac <2.3.0.1005 EoPDell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges and arbitrary code execution. |
|
| CVE-2026-40717 | Aug 03, 2026 |
Dell Monitor driver (<1.0.0.0) Improper Link Follow -> Priv EscDell Monitor driver, version 1.0.0.0, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges. |
|
| CVE-2026-46737 | Jul 22, 2026 |
Dell PowerProtect DM <20.2: Improper Input Validation Remote ExecDell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote execution. |
|
| CVE-2026-49499 | Jul 22, 2026 |
Dell PowerProtect Data Manager <20.2.0.0 IAM Incorrect Token Generation (EoP)Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) a Generation of Incorrect Security Tokens vulnerability in the IAM. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. |
|
| CVE-2026-46738 | Jul 22, 2026 |
Dell PowerProtect DM <20.2.0.0: Insecure REST API Input -> Priv EscalationDell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. |
|
| CVE-2026-40712 | Jul 22, 2026 |
Dell PowerProtect DM <20.2.0.0: IMP IN REST API -> Priv EscalationDell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. |
|
| CVE-2026-40714 | Jul 22, 2026 |
Dell PowerProtect DM <20.2.0.0 Improper Input Validation Priv EscalationDell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. |
|
| CVE-2026-44276 | Jul 22, 2026 |
Dell PowerProtect Data Manager REST API Sensitive Info Exposure v<20.2.0.0Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in the REST API. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure. |
|
| CVE-2026-56687 | Jul 15, 2026 |
Dell ThinOS 10 <2605_10.2100 UI Vulnerability: Unauthorized AccessDell ThinOS 10, versions prior to 2605_10.2100, contain an Obsolete Feature in UI vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access. |
|
| CVE-2026-56087 | Jul 15, 2026 |
Dell ThinOS 10 PMF Vulnerability (<2605_10.2100) - Physical Access RiskDell ThinOS 10, versions prior to 2605_10.2100 contain a Protection Mechanism Failure vulnerability. An attacker with physical access could potentially exploit this vulnerability, leading to unauthorized access to encrypted data. |
|
| CVE-2026-40633 | Jul 15, 2026 |
Dell PowerScale OneFS 9.13.0.2 Logfile Sensitive Info DisclosureDell PowerScale OneFS versions 9.5.0.0 through 9.10.1.7, versions 9.11.0.0 through 9.13.0.2 contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure. |
|
| CVE-2026-49501 | Jul 15, 2026 |
Dell PowerScale OneFS 9.5.0-9.13.0.2 Improper Privilege Escalation (IPM)Dell PowerScale OneFS versions 9.5.0.0 through 9.10.1.7, and versions 9.11.0.0 through 9.13.0.2 contains an Improper Privilege Management vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. |
|
| CVE-2026-54470 | Jul 10, 2026 |
Dell Unisphere for PowerMax v<=10.3.0.5 XEE RCE VulnerabilityDell Unisphere for PowerMax, version(s) 10.3.0.5 and prior contain(s) an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. |
|
| CVE-2026-54469 | Jul 10, 2026 |
Dell Unisphere for PowerMax 10.3.0.5 Deserialization Leads to Root ExecDell Unisphere for PowerMax, version(s) 10.3.0.5 and prior, contain(s) a Deserialization of Untrusted Data vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to arbitrary command execution with root privileges. |
|
| CVE-2026-54468 | Jul 10, 2026 |
Dell Unisphere for PowerMax pre-10.3.0.5 Path Traversal File ReadDell Unisphere for PowerMax, version(s) 10.3.0.5 and prior, contain(s) a path traversal vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability to read arbitrary files. |
|
| CVE-2026-56688 | Jul 10, 2026 |
Dell PowerFlex Manager <5.1.0.1: OS Command InjectionDell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability during OS Repository processing to achieve arbitrary command execution as root, potentially leading to full appliance compromise and lateral movement into managed infrastructure. |
|
| CVE-2026-56689 | Jul 10, 2026 |
Dell PowerFlex Manager <=5.1.0.1 SQL InjectionDell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure. |
|
| CVE-2026-56690 | Jul 10, 2026 |
Dell PowerFlex Manager <5.1.0.1 SQL Injection VulnerabilityDell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure, Information exposure, and Unauthorized access. |
|
| CVE-2026-53480 | Jul 08, 2026 |
Dell PowerProtect Data Domain Path Traversal < 8.8 (LTS)Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper limitation of a pathname to a restricted directory ('path traversal') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized file modification. |