Dell
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Dell product.
RSS Feeds for Dell security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Dell products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Dell Sorted by Most Security Vulnerabilities since 2018
Known Exploited Dell Vulnerabilities
The following Dell vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.
| Title | Description | Added |
|---|---|---|
| Dell RecoverPoint for Virtual Machines (RP4VMs) Use of Hard-coded Credentials Vulnerability |
Dell RecoverPoint for Virtual Machines (RP4VMs) contains an use of hard-coded credentials vulnerability that could allow an unauthenticated remote attacker to gain unauthorized access to the underlying operating system and root-level persistence. CVE-2026-22769 Exploit Probability: 13.1% |
February 18, 2026 |
| Dell dbutil Driver Insufficient Access Control Vulnerability |
Dell dbutil driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial-of-service, or information disclosure. CVE-2021-21551 Exploit Probability: 53.1% |
March 31, 2022 |
2 known exploited Dell vulnerabilities are in the top 5% (95th percentile or greater) of the EPSS exploit probability rankings.
By the Year
In 2026 there have been 274 vulnerabilities in Dell with an average score of 6.6 out of ten. Last year, in 2025 Dell had 204 security vulnerabilities published. That is, 70 more vulnerabilities have already been reported in 2026 as compared to last year. Last year, the average CVE base score was greater by 0.14
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 274 | 6.63 |
| 2025 | 204 | 6.77 |
| 2024 | 219 | 7.07 |
| 2023 | 168 | 6.97 |
| 2022 | 129 | 7.20 |
| 2021 | 139 | 6.94 |
| 2020 | 35 | 7.45 |
| 2019 | 54 | 7.32 |
| 2018 | 57 | 7.21 |
It may take a day or so for new Dell vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Dell Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-63693 | Aug 24, 2026 |
Dell BIOS Improper Link Resolution (Link Following) VulnerabilityDell Client BIOS contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Arbitrary Write |
|
| CVE-2026-61419 | Aug 24, 2026 |
Dell ThinOS 10 Improper Access Control Before 2605_10.2518Dell ThinOS 10, versions prior to 2605_10.2518, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access. |
|
| CVE-2026-53477 | Aug 19, 2026 |
Dell Command Update (DCU) TOCTOU Race Condition EoP in <5.7.1Dell Command Update (DCU), versions prior to 5.7.1, contain a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges. |
|
| CVE-2026-58564 | Aug 19, 2026 |
Dell Command Update <5.7.1 Default Perms: Low Priv Local FS AccessDell Command Update (DCU), versions prior to 5.7.1, contain an Incorrect Default Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Filesystem access for attacker. |
|
| CVE-2026-67268 | Aug 19, 2026 |
DCU <5.7.0 XXE Local Privilege EscalationDell Command Update (DCU), versions prior to 5.7.1, contain an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges and Server-side request forgery. |
|
| CVE-2026-58565 | Aug 19, 2026 |
Dell Command Update <5.7.1 Missing Auth, Priv EscalationDell Command Update (DCU), versions prior to 5.7.1, contain a Missing Authorization vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges. |
|
| CVE-2026-67266 | Aug 19, 2026 |
Dell Command Update (DCU) <5.7.1: Incorrect Auth -> Priv EscalationDell Command Update (DCU), versions prior to 5.7.1, contain an Incorrect Authorization vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. |
|
| CVE-2026-58562 | Aug 19, 2026 |
Dell Command Update (DCU) <5.7.1: Missing Authorization (Unauth)Dell Command Update (DCU), versions prior to 5.7.1, contain a Missing Authorization vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access. |
|
| CVE-2026-67267 | Aug 19, 2026 |
Dell Command Update <=5.7.1 Local Low Priv Info DisclosureDell Command Update (DCU), versions prior to 5.7.1, contain an Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure. |
|
| CVE-2026-56797 | Aug 19, 2026 |
Dell Command Update <=5.7.1 TOCTOU EC PrivilegesDell Command Update (DCU), versions prior to 5.7.1, a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges. |
|
| CVE-2026-49816 | Aug 19, 2026 |
Dell Command Update <5.7.1 Deserialisation of Untrusted Data v0EoPDell Command Update (DCU), versions prior to 5.7.1, contain a Deserialization of Untrusted Data vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges. |
|
| CVE-2026-49817 | Aug 19, 2026 |
Dell Command Update <5.7.1 Deserialization VulnerabilityDell Command Update (DCU), versions prior to 5.7.1, contain a Deserialization of Untrusted Data vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges. |
|
| CVE-2026-56796 | Aug 19, 2026 |
Dell DCU <=v5.7.1 Improper Link Resolution -> Priv EscalationDell Command Update (DCU), versions prior to 5.7.1, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges. |
|
| CVE-2026-23501 | Aug 19, 2026 |
Dell RecoverPoint 6.0.3/6.0.3.1 OS Cmd InjectionDell RecoverPoint for VMs, versions 6.0.3 and 6.0.3.1, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution. |
|
| CVE-2026-32802 | Aug 19, 2026 |
Dell PowerPath 7.2-8.0 SP1 Improper Privilege mgmt: Local Low-Priv ElevationDell PowerPath, version 7.2 through to 8.0 SP1, contains an Improper Privilege Management vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. |
|
| CVE-2026-71176 | Aug 19, 2026 |
Dell OpenManage Enterprise <4.7.0 SQLi Vulnerability (Improper Escape)Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure. |
|
| CVE-2026-54793 | Aug 19, 2026 |
XSS in Dell OpenManage Enterprise <4.7.0 (Improper Input Neutralization)Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure. |
|
| CVE-2026-54794 | Aug 19, 2026 |
Dell OpenManage Enterprise SSRF before 4.7.0 Unauthenticated Graph APIDell OpenManage Enterprise, versions prior to 4.7.0, contains a Server-Side Request Forgery (SSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information exposure. |
|
| CVE-2026-70424 | Aug 19, 2026 |
Dell OpenManage Enterprise 4.6.x Path Traversal Before 4.7.0Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure. |
|
| CVE-2026-70422 | Aug 19, 2026 |
Dell OpenManage Enterprise <4.7.0: SQL Injection via Script InjectionDell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection. |
|
| CVE-2026-70423 | Aug 19, 2026 |
Dell OpenManage Enterprise 4.7.0- Prev, XEE Improper Restriction Exposing InfoDell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure. |
|
| CVE-2026-56088 | Aug 19, 2026 |
Dell OM Enterprise SQLi before v4.7.0 (Improper Neutralization of Special Elements)Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection. |
|
| CVE-2026-54795 | Aug 19, 2026 |
Dell OM Enterprise <4.7.0 OS Cmd Inj CVE-2026-54795Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution. |
|
| CVE-2026-70421 | Aug 19, 2026 |
Dell OpenManage Enterprise Improper Privilege Management (4.6)Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Privilege Management vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. |
|
| CVE-2026-54796 | Aug 19, 2026 |
Dell OpenManage Enterprise <4.7.0 OS Command Injection (High Privileged Remote)Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution. |
|
| CVE-2026-59915 | Aug 18, 2026 |
Dell Alienware Command Center 6.14.20.0 Least Priv Violation Priv EscalationDell Alienware Command Center (AWCC), versions prior to 6.14.20.0, contain a Least Privilege Violation vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges. |
|
| CVE-2026-49500 | Aug 18, 2026 |
Alienware Command Center <=6.14.20.0 Improper Link Following VulnerabilityDell Alienware Command Center (AWCC), versions prior to 6.14.20.0, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Denial of Service and Elevation of Privileges. |
|
| CVE-2026-32657 | Aug 18, 2026 |
Dell Systems Symlink Follow PrivEsc (AppSync 4.6.0.0, UCC Edge 3.0.1)Dell AppSync Version 4.6.0.0, Dell Metro Node Version 8.0.0, Dell UCC Edge Version 3.0.1, Dell VxRail Version 8.0.322, Dell PowerMax Version 10.3.0, Dell Unity Version 5.4, Dell PowerFlex Manager Version 4.5.4, Dell PowerFlex Intelligent Catalog Versions 46.377.00 and 46.382.00 and Dell PowerFlex Rack version 4.5.4 and prior versions, contain(s) an UNIX Symbolic Link (Symlink) Following vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. |
|
| CVE-2026-67262 | Aug 18, 2026 |
Dell PowerStore Missing Auth: LUN Access BypassDell PowerStore contains a Missing Authorization vulnerability. An attacker with access to a mapped host could exploit this vulnerability to read from or write to LUNs that the host is not authorized to access, bypassing per-initiator LUN access controls and leading to protection mechanism bypass. |
|
| CVE-2026-70415 | Aug 18, 2026 |
Dell PowerStore SDNAS NFS/RPC Buffer Copy Without Size Check RCE/DoSDell PowerStore SDNAS contains a Buffer Copy without Checking Size of Input vulnerability in the NFS/RPC. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Command execution and Denial of service. |
|
| CVE-2026-67271 | Aug 18, 2026 |
Dell PowerStore SDNAS SMB/OOB Write Exploit Enables RCEDell PowerStore SDNAS, contains an Out-of-bounds Write vulnerability in the SMB/CIFS. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Denial of service and Remote execution. This is a Critical vulnerability as a remote user could send a specially crafted SMB packet and cause a crash, that is persistent in case automatic restarts are enabled. Additionally, a more sophisticated attacker could use the same vulnerability for Remote Code execution. |
|
| CVE-2026-61407 | Aug 18, 2026 |
Dell Watchdog Timer Driver <=2.0.0.0 Exposed IOCTL allows PrivEscDell Watchdog Timer Driver versions prior to 2.0.0.1 contain an Exposed IOCTL with Insufficient Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Privilege Escalation. |
|
| CVE-2026-56089 | Aug 17, 2026 |
Dell ObjectScale <=4.3.0.1 Path Traversal (Info Disclosure)Dell ObjectScale, versions prior to 4.3.0.1, contain(s) a Path Traversal vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure. |
|
| CVE-2026-59911 | Aug 17, 2026 |
Dell ObjectScale <4.3.0.1 svc_tools: Sensitive Info Logged - InfoDisclosureDell ObjectScale, versions prior to 4.3.0.1, contain(s) an Insertion of Sensitive Information into Log File vulnerability in the svc_tools. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure. |
|
| CVE-2026-59909 | Aug 17, 2026 |
Dell ObjectScale <4.3.0.1 Path Traversal - Low Privileged Local AccessDell ObjectScale, versions prior to 4.3.0.1, contain(s) a Path Traversal vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information tampering. |
|
| CVE-2026-56090 | Aug 17, 2026 |
Dell ObjectScale <4.3.0.1: UncSearchPathElement LPEDell ObjectScale, versions prior to 4.3.0.1, contain(s) an Uncontrolled Search Path Element vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. |
|
| CVE-2026-56685 | Aug 17, 2026 |
Dell ObjectScale v<4.3.0.1: OS Command Injection via Improper NeutralizationDell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution. |
|
| CVE-2026-59910 | Aug 17, 2026 |
Dell ObjectScale OS Command Injection (pre-4.3.0.1) Priv EscDell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. |
|
| CVE-2026-56686 | Aug 17, 2026 |
Dell ObjectScale <4.3.0.1 OS Command Injection Privilege EscalationDell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. |
|
| CVE-2026-70412 | Aug 17, 2026 |
Dell iDRAC9/10 < 7.20.30.50/1.20.60.50: Remanent Memory Read (Info Disclosure)Dell iDRAC9, versions prior to 7.20.30.50, and Dell iDRAC10, version prior to 1.20.60.50, contain a Remanent Data Readable after Memory Erase vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure. |
|
| CVE-2026-63700 | Aug 14, 2026 |
Dell Wyse Management Suite <=2605.0.2 Incorrect Default PermissionDell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Incorrect Default Permission vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Privilege Escalation. |
|
| CVE-2026-66271 | Aug 14, 2026 |
Dell WMS <2605.0.2: Unrestricted Dangerous File Upload RCEDell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Unrestricted Upload of File with Dangerous Type vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote Code Execution. |
|
| CVE-2026-66270 | Aug 14, 2026 |
Dell Wyse Management Suite <2605.0.2 Unrestricted File Upload RCEDell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Unrestricted Upload of File with Dangerous Type vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote Code Execution. |
|
| CVE-2026-66272 | Aug 14, 2026 |
Missing Auth in Dell Wyse WMS (pre2605.0.2)Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure. |
|
| CVE-2026-63701 | Aug 14, 2026 |
Dell Wyse Management Suite 2605 < 2605.0.2 Improper Deserialization PrivEscDell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Improper Deserialization of Untrusted Data vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Privilege Escalation. |
|
| CVE-2026-63702 | Aug 14, 2026 |
Dell WMS <2605.0.2: Hardcoded Creds VulnerabilityDell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain a Use of Hard-coded Credentials vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access. |
|
| CVE-2026-46731 | Aug 12, 2026 |
Dell DDPM Windows 2.3.0.17 Auth Bypass Spoofing (EOP)Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain an Authentication Bypass by Spoofing vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges and arbitrary code execution. |
|
| CVE-2026-59914 | Aug 12, 2026 |
Auth Bypass in Dell DDPM (<2.3.0.17) allows local elevationDell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain an Authentication Bypass by Spoofing vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges and arbitrary code execution. |
|
| CVE-2026-59917 | Aug 12, 2026 |
Dell DDPM 2.3.0.17 Improper Access Control PrivEsc (DDPM)Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges and arbitrary code execution. |
|
| CVE-2026-59916 | Aug 12, 2026 |
Dell DDPM Improper Access Control Privilege Escalation (pre v2.3.0.17)Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges and arbitrary code execution. |