Dell
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Dell product.
RSS Feeds for Dell security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Dell products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Dell Sorted by Most Security Vulnerabilities since 2018
Known Exploited Dell Vulnerabilities
The following Dell vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.
| Title | Description | Added |
|---|---|---|
| Dell RecoverPoint for Virtual Machines (RP4VMs) Use of Hard-coded Credentials Vulnerability |
Dell RecoverPoint for Virtual Machines (RP4VMs) contains an use of hard-coded credentials vulnerability that could allow an unauthenticated remote attacker to gain unauthorized access to the underlying operating system and root-level persistence. CVE-2026-22769 Exploit Probability: 13.1% |
February 18, 2026 |
| Dell dbutil Driver Insufficient Access Control Vulnerability |
Dell dbutil driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial-of-service, or information disclosure. CVE-2021-21551 Exploit Probability: 79.2% |
March 31, 2022 |
The vulnerability CVE-2021-21551: Dell dbutil Driver Insufficient Access Control Vulnerability is in the top 1% of the currently known exploitable vulnerabilities. The vulnerability CVE-2026-22769: Dell RecoverPoint for Virtual Machines (RP4VMs) Use of Hard-coded Credentials Vulnerability is in the top 5% of the currently known exploitable vulnerabilities.
By the Year
In 2026 there have been 301 vulnerabilities in Dell with an average score of 6.7 out of ten. Last year, in 2025 Dell had 204 security vulnerabilities published. That is, 97 more vulnerabilities have already been reported in 2026 as compared to last year. Last year, the average CVE base score was greater by 0.03
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 301 | 6.74 |
| 2025 | 204 | 6.77 |
| 2024 | 219 | 7.07 |
| 2023 | 168 | 6.97 |
| 2022 | 129 | 7.20 |
| 2021 | 139 | 6.94 |
| 2020 | 35 | 7.45 |
| 2019 | 54 | 7.32 |
| 2018 | 57 | 7.21 |
It may take a day or so for new Dell vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Dell Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-58566 | Sep 01, 2026 |
Dell PowerStore: Elevation of Privileges via Incorrect AuthDell PowerStore, an Incorrect Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. |
|
| CVE-2026-79687 | Sep 01, 2026 |
Dell PowerStore SDNAS Missing Auth for Critical Function (Filesystem Access)Dell PowerStore SDNAS contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access. |
|
| CVE-2026-58567 | Sep 01, 2026 |
Dell PowerStore OS Cmd Injection Root EscalationDell PowerStore contains an OS Command Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary commands with root privileges. |
|
| CVE-2026-79682 | Sep 01, 2026 |
Dell PowerStore Cmd Injection Root ExecDell PowerStore contains a Command Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary commands with root privileges. |
|
| CVE-2026-58569 | Sep 01, 2026 |
Dell PowerStore Untrusted Control Sphere Inclusion VulnerabilityDell PowerStore contains an Inclusion of Functionality from Untrusted Control Sphere vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary code with root privileges.. |
|
| CVE-2026-79685 | Sep 01, 2026 |
Dell PowerStore Argument Injection: LimitedPrivileged User Access EscalationDell PowerStore contains an Argument Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to gain unauthorized access to sensitive sensitive system information. |
|
| CVE-2026-79686 | Sep 01, 2026 |
Dell PowerStore PMF Bypass by Authenticated User for Priv EscDell PowerStore contains a Protection Mechanism Failure vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to bypass access restrictions and gain escalated privileges. |
|
| CVE-2026-58571 | Sep 01, 2026 |
Dell PowerStore OS Command Injection Allows Root Privilege EscalationDell PowerStore contains an OS Command Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary commands with root privileges. |
|
| CVE-2026-79684 | Sep 01, 2026 |
Dell PowerStore Priv Escalation via Protection Mechanism FailureDell PowerStore contains a Protection Mechanism Failure vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to bypass access restrictions and gain escalated privileges. |
|
| CVE-2026-58572 | Sep 01, 2026 |
Dell PowerStore Code Injection CVE-2026-58572 (Root Exec)Dell PowerStore contains a Code Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary code with root privileges. |
|
| CVE-2026-79683 | Sep 01, 2026 |
Protection Mechanism Failure: Dell PowerStore Arbitrary FS WriteDell PowerStore contains a Protection Mechanism Failure vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to write attacker-controlled content to arbitrary filesystem paths. |
|
| CVE-2026-58575 | Sep 01, 2026 |
Dell PowerStore Auth Bypass Spoofing Allows Privilege EscalationDell PowerStore contains an Authentication Bypass by Spoofing vulnerability. An authenticated attacker could potentially exploit this vulnerability to escalate privileges to Administrator. |
|
| CVE-2026-76111 | Sep 01, 2026 |
Dell PowerStore Incorrect Auth Privilege EscalationDell PowerStore contains an Incorrect Authorization vulnerability. An authenticated attacker with low privileges could potentially exploit this vulnerability to invoke administrator-only operations, leading to privilege escalation. |
|
| CVE-2026-58574 | Aug 31, 2026 |
Dell PowerStore Missing Auth to Read System Files via Mgt InterfaceDell PowerStore contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with network access to the restricted management interface could potentially exploit this vulnerability to read internal system information from the appliance filesystem. This is a Critical vulnerability as it could expose sensitive information and credentials which allow full administrative access to the array. |
|
| CVE-2026-79938 | Aug 26, 2026 |
Dell PowerProtect Cyber Recovery <20.3 Improper Auth VulnerabilityDell PowerProtect Cyber Recovery, versions prior to 20.3, contain an Improper Authentication vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. |
|
| CVE-2026-79939 | Aug 26, 2026 |
Dell PowerProtect Cyber Recovery <20.3: Symlink Following Script InjectionDell PowerProtect Cyber Recovery, versions Prior to 20.3, contain an UNIX Symbolic Link (Symlink) Following vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Script injection. |
|
| CVE-2026-49809 | Aug 26, 2026 |
SQLI in Dell PowerProtect Cyber Recovery 20.2Dell PowerProtect Cyber Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure. |
|
| CVE-2026-74770 | Aug 26, 2026 |
Dell PowerProtect One 20.1.0.0 and earlier: OS Command InjectionDell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution. |
|
| CVE-2026-74771 | Aug 26, 2026 |
Dell PowerProtect One <=20.1.0.0 Auth Bypass via UserControlled KeyDell PowerProtect One, versions 20.1.0.0 and below, contain an Authorization Bypass Through User-Controlled Key vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information tampering. |
|
| CVE-2026-74774 | Aug 26, 2026 |
Dell PowerProtect One v20.1.0.0 - Improper Cert Validation, Protection BypassDell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass. |
|
| CVE-2026-67275 | Aug 26, 2026 |
Dell PowerProtect One <=20.1.0.0 Cache Poison via Insuf. Trust Comp.Dell PowerProtect One, versions 20.1.0.0 and below, contain a Reliance on Insufficiently Trustworthy Component vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Cache poisoning. |
|
| CVE-2026-68861 | Aug 26, 2026 |
Dell PowerProtect One <=20.1.0.0 OS Command Injection (CVE-2026-68861)Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote execution. |
|
| CVE-2026-68863 | Aug 26, 2026 |
Dell PowerProtect One 20.1.0.0- Stack Buffer Overflow (CVE-2026-68863)Dell PowerProtect One, versions 20.1.0.0 and below, contain a Stack-based Buffer Overflow vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Denial of service. |
|
| CVE-2026-71172 | Aug 26, 2026 |
SSRF in Dell Cloud Disaster Recovery <=20.2Dell Cloud Disaster Recovery, versions 20.2 and prior, contain a Server-Side Request Forgery (SSRF) vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Server-side request forgery. |
|
| CVE-2026-71171 | Aug 26, 2026 |
Dell Cloud Disaster Recovery <20.2 OS Command Injection in REST APIDell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote execution. |
|
| CVE-2026-70419 | Aug 26, 2026 |
Dell Cloud Disaster Recovery 20.2 OS Command Injection VulnerabilityDell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution. |
|
| CVE-2026-79940 | Aug 26, 2026 |
Unauthenticated Remote Access: Improper Access Control in Dell iDRAC9 <7.20.30.50Dell iDRAC9, 14G versions prior to 7.00.00.182 and 15G/16G versions prior to 7.20.30.50, contains an Improper Access Control vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to gaining access to unauthorized data. |
|
| CVE-2026-63693 | Aug 24, 2026 |
Dell BIOS Improper Link Resolution (Link Following) VulnerabilityDell Client BIOS contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Arbitrary Write |
|
| CVE-2026-61419 | Aug 24, 2026 |
Dell ThinOS 10 Improper Access Control Before 2605_10.2518Dell ThinOS 10, versions prior to 2605_10.2518, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access. |
|
| CVE-2026-53477 | Aug 19, 2026 |
Dell Command Update (DCU) TOCTOU Race Condition EoP in <5.7.1Dell Command Update (DCU), versions prior to 5.7.1, contain a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges. |
|
| CVE-2026-58564 | Aug 19, 2026 |
Dell Command Update <5.7.1 Default Perms: Low Priv Local FS AccessDell Command Update (DCU), versions prior to 5.7.1, contain an Incorrect Default Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Filesystem access for attacker. |
|
| CVE-2026-67268 | Aug 19, 2026 |
DCU <5.7.0 XXE Local Privilege EscalationDell Command Update (DCU), versions prior to 5.7.1, contain an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges and Server-side request forgery. |
|
| CVE-2026-58565 | Aug 19, 2026 |
Dell Command Update <5.7.1 Missing Auth, Priv EscalationDell Command Update (DCU), versions prior to 5.7.1, contain a Missing Authorization vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges. |
|
| CVE-2026-67266 | Aug 19, 2026 |
Dell Command Update (DCU) <5.7.1: Incorrect Auth -> Priv EscalationDell Command Update (DCU), versions prior to 5.7.1, contain an Incorrect Authorization vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. |
|
| CVE-2026-58562 | Aug 19, 2026 |
Dell Command Update (DCU) <5.7.1: Missing Authorization (Unauth)Dell Command Update (DCU), versions prior to 5.7.1, contain a Missing Authorization vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access. |
|
| CVE-2026-67267 | Aug 19, 2026 |
Dell Command Update <=5.7.1 Local Low Priv Info DisclosureDell Command Update (DCU), versions prior to 5.7.1, contain an Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure. |
|
| CVE-2026-56797 | Aug 19, 2026 |
Dell Command Update <=5.7.1 TOCTOU EC PrivilegesDell Command Update (DCU), versions prior to 5.7.1, a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges. |
|
| CVE-2026-49816 | Aug 19, 2026 |
Dell Command Update <5.7.1 Deserialisation of Untrusted Data v0EoPDell Command Update (DCU), versions prior to 5.7.1, contain a Deserialization of Untrusted Data vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges. |
|
| CVE-2026-49817 | Aug 19, 2026 |
Dell Command Update <5.7.1 Deserialization VulnerabilityDell Command Update (DCU), versions prior to 5.7.1, contain a Deserialization of Untrusted Data vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges. |
|
| CVE-2026-56796 | Aug 19, 2026 |
Dell DCU <=v5.7.1 Improper Link Resolution -> Priv EscalationDell Command Update (DCU), versions prior to 5.7.1, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges. |
|
| CVE-2026-23501 | Aug 19, 2026 |
Dell RecoverPoint 6.0.3/6.0.3.1 OS Cmd InjectionDell RecoverPoint for VMs, versions 6.0.3 and 6.0.3.1, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution. |
|
| CVE-2026-32802 | Aug 19, 2026 |
Dell PowerPath 7.2-8.0 SP1 Improper Privilege mgmt: Local Low-Priv ElevationDell PowerPath, version 7.2 through to 8.0 SP1, contains an Improper Privilege Management vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. |
|
| CVE-2026-71176 | Aug 19, 2026 |
Dell OpenManage Enterprise <4.7.0 SQLi Vulnerability (Improper Escape)Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure. |
|
| CVE-2026-54793 | Aug 19, 2026 |
XSS in Dell OpenManage Enterprise <4.7.0 (Improper Input Neutralization)Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure. |
|
| CVE-2026-54794 | Aug 19, 2026 |
Dell OpenManage Enterprise SSRF before 4.7.0 Unauthenticated Graph APIDell OpenManage Enterprise, versions prior to 4.7.0, contains a Server-Side Request Forgery (SSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information exposure. |
|
| CVE-2026-70424 | Aug 19, 2026 |
Dell OpenManage Enterprise 4.6.x Path Traversal Before 4.7.0Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure. |
|
| CVE-2026-70422 | Aug 19, 2026 |
Dell OpenManage Enterprise <4.7.0: SQL Injection via Script InjectionDell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection. |
|
| CVE-2026-70423 | Aug 19, 2026 |
Dell OpenManage Enterprise 4.7.0- Prev, XEE Improper Restriction Exposing InfoDell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure. |
|
| CVE-2026-56088 | Aug 19, 2026 |
Dell OM Enterprise SQLi before v4.7.0 (Improper Neutralization of Special Elements)Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection. |
|
| CVE-2026-54795 | Aug 19, 2026 |
Dell OM Enterprise <4.7.0 OS Cmd Inj CVE-2026-54795Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution. |
|