Dell
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Dell product.
RSS Feeds for Dell security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Dell products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Dell Sorted by Most Security Vulnerabilities since 2018
Known Exploited Dell Vulnerabilities
The following Dell vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.
| Title | Description | Added |
|---|---|---|
| Dell RecoverPoint for Virtual Machines (RP4VMs) Use of Hard-coded Credentials Vulnerability |
Dell RecoverPoint for Virtual Machines (RP4VMs) contains an use of hard-coded credentials vulnerability that could allow an unauthenticated remote attacker to gain unauthorized access to the underlying operating system and root-level persistence. CVE-2026-22769 Exploit Probability: 13.1% |
February 18, 2026 |
| Dell dbutil Driver Insufficient Access Control Vulnerability |
Dell dbutil driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial-of-service, or information disclosure. CVE-2021-21551 Exploit Probability: 79.2% |
March 31, 2022 |
The vulnerability CVE-2021-21551: Dell dbutil Driver Insufficient Access Control Vulnerability is in the top 1% of the currently known exploitable vulnerabilities. The vulnerability CVE-2026-22769: Dell RecoverPoint for Virtual Machines (RP4VMs) Use of Hard-coded Credentials Vulnerability is in the top 5% of the currently known exploitable vulnerabilities.
By the Year
In 2026 there have been 348 vulnerabilities in Dell with an average score of 6.7 out of ten. Last year, in 2025 Dell had 204 security vulnerabilities published. That is, 144 more vulnerabilities have already been reported in 2026 as compared to last year. Last year, the average CVE base score was greater by 0.05
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 348 | 6.71 |
| 2025 | 204 | 6.77 |
| 2024 | 219 | 7.07 |
| 2023 | 168 | 6.97 |
| 2022 | 129 | 7.20 |
| 2021 | 139 | 6.94 |
| 2020 | 35 | 7.45 |
| 2019 | 54 | 7.32 |
| 2018 | 57 | 7.21 |
It may take a day or so for new Dell vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Dell Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-79636 | Sep 09, 2026 |
Dell SCG 5.0 Improper cert validation (host mismatch) pre5.36.00.16Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Validation of Certificate with Host Mismatch vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access. |
|
| CVE-2026-80123 | Sep 09, 2026 |
Dell SCG 5.0 SSRF prior to 5.36.00.16 & 5.36.00.00Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Server-Side Request Forgery (SSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service. |
|
| CVE-2026-80124 | Sep 09, 2026 |
Dell SCG 5.0 Appliance Prior to 5.36.00.16 Log Sensitive Info ExposureDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information exposure. |
|
| CVE-2026-80177 | Sep 09, 2026 |
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to script injection. |
|
| CVE-2026-80055 | Sep 09, 2026 |
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to script injection. |
|
| CVE-2026-80166 | Sep 07, 2026 |
Dell SCG 5.0 Privilege Escalation (Imp PrivMgt) <5.36.00.16Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Privilege Management vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges. |
|
| CVE-2026-80176 | Sep 07, 2026 |
Dell SCG 5.0 Plaintext Password Storage <=5.36.00.16Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Plaintext Storage of a Password vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information disclosure. |
|
| CVE-2026-79639 | Sep 07, 2026 |
Dell SCG 5.0 Improper Cert Validation <5.36.00.16 (App) / <5.36.00.00 (Appl)Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access. |
|
| CVE-2026-80125 | Sep 07, 2026 |
Dell SCG 5.0 <5.36.00.16: Improper Cert Validation (ICV) VulnerabilityDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access. |
|
| CVE-2026-80167 | Sep 07, 2026 |
Dell SCG 5.0 Appliance <5.36.00.16 Vulnerable to Hard-Coded Crypto KeyDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Cryptographic Key vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information disclosure. |
|
| CVE-2026-80126 | Sep 07, 2026 |
Dell SCG 5.0 Improper Locking (5.36.00.16) Remote Filesystem AccessDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Locking vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to filesystem access for attacker. |
|
| CVE-2026-79975 | Sep 07, 2026 |
Dell SCG 5.0 Improper Cert Validation (v5.36.00.16) SSRF local attackerDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to server-side request forgery. |
|
| CVE-2026-80058 | Sep 07, 2026 |
Dell SCG 5.0 Cleartext Sensitive Info; Unpatched <5.36.00Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Cleartext Storage of Sensitive Information vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information exposure. |
|
| CVE-2026-80127 | Sep 07, 2026 |
Dell SCG 5.0 OS Cmd Injection <5.36.00.16 (Appliance) / <5.36.00.00 (App)Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to elevation of privileges. |
|
| CVE-2026-79642 | Sep 07, 2026 |
Dell SCG 5.0 Improper Cert Validation (pre-5.36.00.16)Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access. |
|
| CVE-2026-79943 | Sep 07, 2026 |
Dell SCG 5.0 Improper Cert Validation (Host Mismatch) before 5.36.00.16 BypassDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Validation of Certificate with Host Mismatch vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to protection mechanism bypass. |
|
| CVE-2026-79691 | Sep 07, 2026 |
Dell SCG 5.0 <5.36.00.16 Improper Cert Val (CVE-2026-79691)Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to protection mechanism bypass. |
|
| CVE-2026-79643 | Sep 07, 2026 |
Dell SCG 5.0 <5.36.00.16: Incorrect Operator Use Remote Unauth AccessDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Incorrect Operator vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access. |
|
| CVE-2026-80054 | Sep 07, 2026 |
Dell SCG 5.0 <5.36.00.16/00: ICPS unauthorized accessDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to unauthorized access. |
|
| CVE-2026-78488 | Sep 07, 2026 |
Dell SCG 5.0 Appliance <5.36.00.16 OS Command InjectionDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to command execution. |
|
| CVE-2026-80056 | Sep 07, 2026 |
Dell SCG 5.0 Appliance <5.36.00.16 Insertion of Sensitive Info into LogDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information exposure. |
|
| CVE-2026-80057 | Sep 07, 2026 |
Dell SCG 5 Appliance <5.36.00.16 UHK Key DisclosureDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Cryptographic Key vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information disclosure. |
|
| CVE-2026-79644 | Sep 07, 2026 |
Dell SCG 5.0 (5.35.99) Improper Cert Validation AttackDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access. |
|
| CVE-2026-79645 | Sep 07, 2026 |
Dell SCG 5.0 Before 5.36.00.16 Missing Auth for Critical FunctionDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access. |
|
| CVE-2026-78480 | Sep 07, 2026 |
Dell SCG 5.0 | Missing Auth for Critical Function pre 5.36.00.16Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access. |
|
| CVE-2026-80170 | Sep 07, 2026 |
Dell SCG 5.0 (pre5.36.00.16) Hardcoded Credentials Remote BypassDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Credentials vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to protection mechanism bypass. |
|
| CVE-2026-79734 | Sep 07, 2026 |
Dell SCG 5 Appliance <=5.36.00.16 Improper Cert Validation VulnerabilityDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to protection mechanism bypass. |
|
| CVE-2026-78487 | Sep 07, 2026 |
Dell SCG 5.0 <5.36.00.16 Hard-coded Crypt Key Info DisclosureDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Cryptographic Key vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information disclosure. |
|
| CVE-2026-80128 | Sep 07, 2026 |
Dell SCG 5.0 Improper Auth Bypass <5.36.00.16 (Appliance) & <5.36.00.00 (App)Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Authentication vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to protection mechanism bypass. |
|
| CVE-2026-80130 | Sep 07, 2026 |
Dell SCG 5.0 Appliance RPT before 5.36.00.16 remote exec riskDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Relative Path Traversal vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to remote execution. |
|
| CVE-2026-80131 | Sep 07, 2026 |
Path Traversal in Dell SCG 5.0 before 5.36.00.16 Enables Remote ExecDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to remote execution. |
|
| CVE-2026-80129 | Sep 07, 2026 |
Dell SCG 5.0 Path Traversal -> Remote Exec <5.36.00.16/5.36.00.00Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to remote execution. |
|
| CVE-2026-80164 | Sep 07, 2026 |
Dell SCG 5.0 Improper Cert Validation <5.36 (Unauth Remote)Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access. |
|
| CVE-2026-80238 | Sep 07, 2026 |
Critical: Dell SCG5.0 Exec w/ Unn Priv via exposed Docker sock (5.36.00.16)Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Execution with Unnecessary Privileges vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Protection mechanism bypass. This vulnerability is considered critical because a low-privileged operator with SSH access to the SCG host can gain root-level access to the host without requiring a password by leveraging the exposed Docker socket. Additionally, an attacker who compromises a service running within the orchestrator container can access the same socket and escape the container boundary to obtain host-level control. Dell recommends that customers upgrade at the earliest opportunity. |
|
| CVE-2026-80178 | Sep 07, 2026 |
Dell SCG 5.0 Appliance Improper Privilege Management, <5.36.00.16Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Privilege Management vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges. |
|
| CVE-2026-80135 | Sep 07, 2026 |
Dell SCG 5.0 Appliance <5.36.00.16: Improper Exception Handling BypassDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Check or Handling of Exceptional Conditions vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to protection mechanism bypass. |
|
| CVE-2026-80132 | Sep 07, 2026 |
Dell SCG 5.0 Missing Auth Remote Exploit (5.36.00.16)ell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access. |
|
| CVE-2026-80133 | Sep 07, 2026 |
Dell SCG 5.0 Appliance <=5.36.00.16 RPT Remote ExecDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Relative Path Traversal vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to remote execution. |
|
| CVE-2026-80134 | Sep 07, 2026 |
Dell SCG 5.0 Appliance/App Hard-Coded Credentials (v<5.36.00.16/00)Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Credentials vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access. |
|
| CVE-2026-61410 | Sep 07, 2026 |
Dell SCG 5.0 Appliance <5.36.00.16: Missing Auth Remote ExecDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing Authorization vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to remote execution. This vulnerability is considered critical because it allows an attacker to execute commands remotely on a target system by sending a specially crafted request to the application, bypassing intended restrictions on code execution.Dell recommends customers to upgrade at the earliest opportunity. |
|
| CVE-2026-61409 | Sep 07, 2026 |
Dell SCG 5.0 OS Command Injection (v<5.36.00.00)Dell Secure Connect Gateway (SCG) 5.0 Application, versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to remote execution. |
|
| CVE-2026-63694 | Sep 03, 2026 |
Cmd Injection in Dell SmartFabric OS10 <10.5.6.14 (Remote)Dell SmartFabric OS10 Software, versions prior to 10.5.6.14, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution. |
|
| CVE-2026-35160 | Sep 03, 2026 |
Dell SmartFabric OS10 <10.5.6.14: OS Command Injection VulnerabilityDell SmartFabric OS10 Software, versions prior to 10.5.6.14, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution. |
|
| CVE-2026-73600 | Sep 03, 2026 |
Dell PowerProtect Data Manager 20.2.0.0- Stack Buffer Overflow in Restore AgentDell PowerProtect Data Manager, versions 20.2.0.0 and below, contain a stack buffer overflow vulnerability in file-level restore agent. A high privileged remote attacker could potentially exploit this vulnerability, leading to Information disclosure. |
|
| CVE-2026-68860 | Sep 03, 2026 |
Dell PowerProtect DM <=20.2.0.0: Remote RLE via Data/Memory LayoutDell PowerProtect Data Manager, versions 20.2.0.0 and below, contain a Reliance on Data/Memory Layout vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to Launch of phishing attacks. |
|
| CVE-2026-74769 | Sep 03, 2026 |
Dell PowerProtect Data Manager <20.2.0.0: REST API Incorrect AuthDell PowerProtect Data Manager, versions 20.2.0.0 and below, contain an Incorrect Authorization vulnerability in the REST API. A low privileged remote attacker could potentially exploit this vulnerability, leading to Protection mechanism bypass. |
|
| CVE-2026-74768 | Sep 03, 2026 |
PowerProtect Data Manager SSRF in REST API (<20.2.0.0)Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain a Server-Side Request Forgery (SSRF) vulnerability in the REST API. A high privileged remote attacker could potentially exploit this vulnerability, leading to Information disclosure. |
|
| CVE-2026-58566 | Sep 01, 2026 |
Dell PowerStore: Elevation of Privileges via Incorrect AuthDell PowerStore, an Incorrect Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. |
|
| CVE-2026-79687 | Sep 01, 2026 |
Dell PowerStore SDNAS Missing Auth for Critical Function (Filesystem Access)Dell PowerStore SDNAS contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access. |
|
| CVE-2026-58567 | Sep 01, 2026 |
Dell PowerStore OS Cmd Injection Root EscalationDell PowerStore contains an OS Command Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary commands with root privileges. |