Dell Dell

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any Dell product.

RSS Feeds for Dell security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in Dell products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by Dell Sorted by Most Security Vulnerabilities since 2018

Dell Powerscale Onefs100 vulnerabilities

Dell Wyse Management Suite62 vulnerabilities

Dell Smartfabric Os1032 vulnerabilities

Dell Unity30 vulnerabilities

Dell Secure Connect Gateway28 vulnerabilities

Dell Bsafe Micro Edition Suite28 vulnerabilities

Dell Powerprotect Data Manager24 vulnerabilities

Dell Command Update23 vulnerabilities

Dell Openmanage Enterprise22 vulnerabilities

Dell Objectscale20 vulnerabilities

Dell Unisphere For Powermax20 vulnerabilities

Dell Alienware Command Center19 vulnerabilities

Dell Bsafe Ssl J19 vulnerabilities

Dell Cloudlink16 vulnerabilities

Dell Supportassist13 vulnerabilities

Dell Elastic Cloud Storage12 vulnerabilities

Dell Networker11 vulnerabilities

Dell Bsafe Crypto J10 vulnerabilities

Dell Insightiq10 vulnerabilities

Dell Networking Os109 vulnerabilities

Dell Appsync8 vulnerabilities

Dell Controlvault38 vulnerabilities

Dell Digital Delivery8 vulnerabilities

Dell Alienware Update7 vulnerabilities

Dell Avamar Server7 vulnerabilities

Dell Repository Manager7 vulnerabilities

Dell Storage Manager7 vulnerabilities

Dell Encryption7 vulnerabilities

Dell Update6 vulnerabilities

Dell Display Manager6 vulnerabilities

Dell Emc Appsync6 vulnerabilities

Dell Thinos6 vulnerabilities

Dell Peripheral Manager6 vulnerabilities

Dell Idrac96 vulnerabilities

Dell Powerstoreos5 vulnerabilities

Dell Command Monitor5 vulnerabilities

Dell Data Lakehouse5 vulnerabilities

Dell Unisphere 3605 vulnerabilities

Dell Enterprise Sonic Os5 vulnerabilities

Dell Power Manager5 vulnerabilities

Dell Common Event Enabler4 vulnerabilities

Dell Powerpath4 vulnerabilities

Known Exploited Dell Vulnerabilities

The following Dell vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.

Title Description Added
Dell RecoverPoint for Virtual Machines (RP4VMs) Use of Hard-coded Credentials Vulnerability Dell RecoverPoint for Virtual Machines (RP4VMs) contains an use of hard-coded credentials vulnerability that could allow an unauthenticated remote attacker to gain unauthorized access to the underlying operating system and root-level persistence.
CVE-2026-22769 Exploit Probability: 13.1%
February 18, 2026
Dell dbutil Driver Insufficient Access Control Vulnerability Dell dbutil driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial-of-service, or information disclosure.
CVE-2021-21551 Exploit Probability: 79.2%
March 31, 2022

The vulnerability CVE-2021-21551: Dell dbutil Driver Insufficient Access Control Vulnerability is in the top 1% of the currently known exploitable vulnerabilities. The vulnerability CVE-2026-22769: Dell RecoverPoint for Virtual Machines (RP4VMs) Use of Hard-coded Credentials Vulnerability is in the top 5% of the currently known exploitable vulnerabilities.

By the Year

In 2026 there have been 301 vulnerabilities in Dell with an average score of 6.7 out of ten. Last year, in 2025 Dell had 204 security vulnerabilities published. That is, 97 more vulnerabilities have already been reported in 2026 as compared to last year. Last year, the average CVE base score was greater by 0.03




Year Vulnerabilities Average Score
2026 301 6.74
2025 204 6.77
2024 219 7.07
2023 168 6.97
2022 129 7.20
2021 139 6.94
2020 35 7.45
2019 54 7.32
2018 57 7.21

It may take a day or so for new Dell vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Dell Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2026-58566 Sep 01, 2026
Dell PowerStore: Elevation of Privileges via Incorrect Auth Dell PowerStore, an Incorrect Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.
CVE-2026-79687 Sep 01, 2026
Dell PowerStore SDNAS Missing Auth for Critical Function (Filesystem Access) Dell PowerStore SDNAS contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access.
CVE-2026-58567 Sep 01, 2026
Dell PowerStore OS Cmd Injection Root Escalation Dell PowerStore contains an OS Command Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary commands with root privileges.
CVE-2026-79682 Sep 01, 2026
Dell PowerStore Cmd Injection Root Exec Dell PowerStore contains a Command Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary commands with root privileges.
CVE-2026-58569 Sep 01, 2026
Dell PowerStore Untrusted Control Sphere Inclusion Vulnerability Dell PowerStore contains an Inclusion of Functionality from Untrusted Control Sphere vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary code with root privileges..
CVE-2026-79685 Sep 01, 2026
Dell PowerStore Argument Injection: LimitedPrivileged User Access Escalation Dell PowerStore contains an Argument Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to gain unauthorized access to sensitive sensitive system information.
CVE-2026-79686 Sep 01, 2026
Dell PowerStore PMF Bypass by Authenticated User for Priv Esc Dell PowerStore contains a Protection Mechanism Failure vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to bypass access restrictions and gain escalated privileges.
CVE-2026-58571 Sep 01, 2026
Dell PowerStore OS Command Injection Allows Root Privilege Escalation Dell PowerStore contains an OS Command Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary commands with root privileges.
CVE-2026-79684 Sep 01, 2026
Dell PowerStore Priv Escalation via Protection Mechanism Failure Dell PowerStore contains a Protection Mechanism Failure vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to bypass access restrictions and gain escalated privileges.
CVE-2026-58572 Sep 01, 2026
Dell PowerStore Code Injection CVE-2026-58572 (Root Exec) Dell PowerStore contains a Code Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary code with root privileges.
CVE-2026-79683 Sep 01, 2026
Protection Mechanism Failure: Dell PowerStore Arbitrary FS Write Dell PowerStore contains a Protection Mechanism Failure vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to write attacker-controlled content to arbitrary filesystem paths.
CVE-2026-58575 Sep 01, 2026
Dell PowerStore Auth Bypass Spoofing Allows Privilege Escalation Dell PowerStore contains an Authentication Bypass by Spoofing vulnerability. An authenticated attacker could potentially exploit this vulnerability to escalate privileges to Administrator.
CVE-2026-76111 Sep 01, 2026
Dell PowerStore Incorrect Auth Privilege Escalation Dell PowerStore contains an Incorrect Authorization vulnerability. An authenticated attacker with low privileges could potentially exploit this vulnerability to invoke administrator-only operations, leading to privilege escalation.
CVE-2026-58574 Aug 31, 2026
Dell PowerStore Missing Auth to Read System Files via Mgt Interface Dell PowerStore contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with network access to the restricted management interface could potentially exploit this vulnerability to read internal system information from the appliance filesystem. This is a Critical vulnerability as it could expose sensitive information and credentials which allow full administrative access to the array.
CVE-2026-79938 Aug 26, 2026
Dell PowerProtect Cyber Recovery <20.3 Improper Auth Vulnerability Dell PowerProtect Cyber Recovery, versions prior to 20.3, contain an Improper Authentication vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.
CVE-2026-79939 Aug 26, 2026
Dell PowerProtect Cyber Recovery <20.3: Symlink Following Script Injection Dell PowerProtect Cyber Recovery, versions Prior to 20.3, contain an UNIX Symbolic Link (Symlink) Following vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Script injection.
CVE-2026-49809 Aug 26, 2026
SQLI in Dell PowerProtect Cyber Recovery 20.2 Dell PowerProtect Cyber Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.
CVE-2026-74770 Aug 26, 2026
Dell PowerProtect One 20.1.0.0 and earlier: OS Command Injection Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution.
CVE-2026-74771 Aug 26, 2026
Dell PowerProtect One <=20.1.0.0 Auth Bypass via UserControlled Key Dell PowerProtect One, versions 20.1.0.0 and below, contain an Authorization Bypass Through User-Controlled Key vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information tampering.
CVE-2026-74774 Aug 26, 2026
Dell PowerProtect One v20.1.0.0 - Improper Cert Validation, Protection Bypass Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass.
CVE-2026-67275 Aug 26, 2026
Dell PowerProtect One <=20.1.0.0 Cache Poison via Insuf. Trust Comp. Dell PowerProtect One, versions 20.1.0.0 and below, contain a Reliance on Insufficiently Trustworthy Component vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Cache poisoning.
CVE-2026-68861 Aug 26, 2026
Dell PowerProtect One <=20.1.0.0 OS Command Injection (CVE-2026-68861) Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.
CVE-2026-68863 Aug 26, 2026
Dell PowerProtect One 20.1.0.0- Stack Buffer Overflow (CVE-2026-68863) Dell PowerProtect One, versions 20.1.0.0 and below, contain a Stack-based Buffer Overflow vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Denial of service.
CVE-2026-71172 Aug 26, 2026
SSRF in Dell Cloud Disaster Recovery <=20.2 Dell Cloud Disaster Recovery, versions 20.2 and prior, contain a Server-Side Request Forgery (SSRF) vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Server-side request forgery.
CVE-2026-71171 Aug 26, 2026
Dell Cloud Disaster Recovery <20.2 OS Command Injection in REST API Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.
CVE-2026-70419 Aug 26, 2026
Dell Cloud Disaster Recovery 20.2 OS Command Injection Vulnerability Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.
CVE-2026-79940 Aug 26, 2026
Unauthenticated Remote Access: Improper Access Control in Dell iDRAC9 <7.20.30.50 Dell iDRAC9, 14G versions prior to 7.00.00.182 and 15G/16G versions prior to 7.20.30.50, contains an Improper Access Control vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to gaining access to unauthorized data.
Idrac9
CVE-2026-63693 Aug 24, 2026
Dell BIOS Improper Link Resolution (Link Following) Vulnerability Dell Client BIOS contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Arbitrary Write
CVE-2026-61419 Aug 24, 2026
Dell ThinOS 10 Improper Access Control Before 2605_10.2518 Dell ThinOS 10, versions prior to 2605_10.2518, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access.
CVE-2026-53477 Aug 19, 2026
Dell Command Update (DCU) TOCTOU Race Condition EoP in <5.7.1 Dell Command Update (DCU), versions prior to 5.7.1, contain a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.
Command Update
CVE-2026-58564 Aug 19, 2026
Dell Command Update <5.7.1 Default Perms: Low Priv Local FS Access Dell Command Update (DCU), versions prior to 5.7.1, contain an Incorrect Default Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Filesystem access for attacker.
Command Update
CVE-2026-67268 Aug 19, 2026
DCU <5.7.0 XXE Local Privilege Escalation Dell Command Update (DCU), versions prior to 5.7.1, contain an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges and Server-side request forgery.
Command Update
CVE-2026-58565 Aug 19, 2026
Dell Command Update <5.7.1 Missing Auth, Priv Escalation Dell Command Update (DCU), versions prior to 5.7.1, contain a Missing Authorization vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.
Command Update
CVE-2026-67266 Aug 19, 2026
Dell Command Update (DCU) <5.7.1: Incorrect Auth -> Priv Escalation Dell Command Update (DCU), versions prior to 5.7.1, contain an Incorrect Authorization vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
Command Update
CVE-2026-58562 Aug 19, 2026
Dell Command Update (DCU) <5.7.1: Missing Authorization (Unauth) Dell Command Update (DCU), versions prior to 5.7.1, contain a Missing Authorization vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access.
Command Update
CVE-2026-67267 Aug 19, 2026
Dell Command Update <=5.7.1 Local Low Priv Info Disclosure Dell Command Update (DCU), versions prior to 5.7.1, contain an Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.
Command Update
CVE-2026-56797 Aug 19, 2026
Dell Command Update <=5.7.1 TOCTOU EC Privileges Dell Command Update (DCU), versions prior to 5.7.1, a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.
Command Update
CVE-2026-49816 Aug 19, 2026
Dell Command Update <5.7.1 Deserialisation of Untrusted Data v0EoP Dell Command Update (DCU), versions prior to 5.7.1, contain a Deserialization of Untrusted Data vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.
Command Update
CVE-2026-49817 Aug 19, 2026
Dell Command Update <5.7.1 Deserialization Vulnerability Dell Command Update (DCU), versions prior to 5.7.1, contain a Deserialization of Untrusted Data vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.
Command Update
CVE-2026-56796 Aug 19, 2026
Dell DCU <=v5.7.1 Improper Link Resolution -> Priv Escalation Dell Command Update (DCU), versions prior to 5.7.1, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.
Command Update
CVE-2026-23501 Aug 19, 2026
Dell RecoverPoint 6.0.3/6.0.3.1 OS Cmd Injection Dell RecoverPoint for VMs, versions 6.0.3 and 6.0.3.1, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.
Recoverpoint Virtual Machines
CVE-2026-32802 Aug 19, 2026
Dell PowerPath 7.2-8.0 SP1 Improper Privilege mgmt: Local Low-Priv Elevation Dell PowerPath, version 7.2 through to 8.0 SP1, contains an Improper Privilege Management vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
Powerpath
CVE-2026-71176 Aug 19, 2026
Dell OpenManage Enterprise <4.7.0 SQLi Vulnerability (Improper Escape) Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.
Openmanage Enterprise
CVE-2026-54793 Aug 19, 2026
XSS in Dell OpenManage Enterprise <4.7.0 (Improper Input Neutralization) Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.
Openmanage Enterprise
CVE-2026-54794 Aug 19, 2026
Dell OpenManage Enterprise SSRF before 4.7.0 Unauthenticated Graph API Dell OpenManage Enterprise, versions prior to 4.7.0, contains a Server-Side Request Forgery (SSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.
Openmanage Enterprise
CVE-2026-70424 Aug 19, 2026
Dell OpenManage Enterprise 4.6.x Path Traversal Before 4.7.0 Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.
Openmanage Enterprise
CVE-2026-70422 Aug 19, 2026
Dell OpenManage Enterprise <4.7.0: SQL Injection via Script Injection Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection.
Openmanage Enterprise
CVE-2026-70423 Aug 19, 2026
Dell OpenManage Enterprise 4.7.0- Prev, XEE Improper Restriction Exposing Info Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.
Openmanage Enterprise
CVE-2026-56088 Aug 19, 2026
Dell OM Enterprise SQLi before v4.7.0 (Improper Neutralization of Special Elements) Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection.
Openmanage Enterprise
CVE-2026-54795 Aug 19, 2026
Dell OM Enterprise <4.7.0 OS Cmd Inj CVE-2026-54795 Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.
Openmanage Enterprise
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.