Dell
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Dell product.
RSS Feeds for Dell security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Dell products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Dell Sorted by Most Security Vulnerabilities since 2018
Known Exploited Dell Vulnerabilities
The following Dell vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.
| Title | Description | Added |
|---|---|---|
| Dell RecoverPoint for Virtual Machines (RP4VMs) Use of Hard-coded Credentials Vulnerability |
Dell RecoverPoint for Virtual Machines (RP4VMs) contains an use of hard-coded credentials vulnerability that could allow an unauthenticated remote attacker to gain unauthorized access to the underlying operating system and root-level persistence. CVE-2026-22769 Exploit Probability: 13.1% |
February 18, 2026 |
| Dell dbutil Driver Insufficient Access Control Vulnerability |
Dell dbutil driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial-of-service, or information disclosure. CVE-2021-21551 Exploit Probability: 79.2% |
March 31, 2022 |
The vulnerability CVE-2021-21551: Dell dbutil Driver Insufficient Access Control Vulnerability is in the top 1% of the currently known exploitable vulnerabilities. The vulnerability CVE-2026-22769: Dell RecoverPoint for Virtual Machines (RP4VMs) Use of Hard-coded Credentials Vulnerability is in the top 5% of the currently known exploitable vulnerabilities.
By the Year
In 2026 there have been 435 vulnerabilities in Dell with an average score of 6.6 out of ten. Last year, in 2025 Dell had 204 security vulnerabilities published. That is, 231 more vulnerabilities have already been reported in 2026 as compared to last year. Last year, the average CVE base score was greater by 0.17
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 435 | 6.60 |
| 2025 | 204 | 6.77 |
| 2024 | 219 | 7.07 |
| 2023 | 168 | 6.97 |
| 2022 | 129 | 7.20 |
| 2021 | 139 | 6.94 |
| 2020 | 35 | 7.45 |
| 2019 | 54 | 7.32 |
| 2018 | 57 | 7.21 |
It may take a day or so for new Dell vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Dell Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-70416 | Sep 16, 2026 |
Dell ObjectScale, versions prior to 4.4.0.0, contains a Deserialization of Untrusted Data vulnerabilityDell ObjectScale, versions prior to 4.4.0.0, contains a Deserialization of Untrusted Data vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution. |
|
| CVE-2026-76104 | Sep 16, 2026 |
Dell ObjectScale, versions prior to 4.4.0.0, contains an Incorrect Permission Assignment for Critical Resource vulnerability in the OSDell ObjectScale, versions prior to 4.4.0.0, contains an Incorrect Permission Assignment for Critical Resource vulnerability in the OS. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Denial of service. |
|
| CVE-2026-26947 | Sep 16, 2026 |
Dell ECS versions 3.8.1.0 through 3.8.1.7Dell ECS versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.4.0.0, contains an Improper Privilege Management vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. |
|
| CVE-2025-43936 | Sep 16, 2026 |
Dell ObjectScale, versions prior to ObjectScale 4.4.0.0, contains an Improper Authentication vulnerabilityDell ObjectScale, versions prior to ObjectScale 4.4.0.0, contains an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. |
|
| CVE-2025-36591 | Sep 16, 2026 |
Dell ECS versions 3.8.1.0 through 3.8.1.7Dell ECS versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.4.0.0, contains an Use of a Broken or Risky Cryptographic Algorithm vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure. |
|
| CVE-2026-81237 | Sep 15, 2026 |
Dell Wyse MS Improper Auth (pre-2605.0.3.683)Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. |
|
| CVE-2026-81238 | Sep 15, 2026 |
Dell Wyse Management Suite 2605.0.3.683 Missing Auth RCE VULNDell Wyse Management Suite, versions prior to 2605.0.3.683, contain a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. |
|
| CVE-2026-81235 | Sep 15, 2026 |
Missing Crypto Step in Dell Wyse MS < 2605.0.3.683 Causes Info TamperingDell Wyse Management Suite, versions prior to 2605.0.3.683, contain a Missing Cryptographic Step vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information tampering. |
|
| CVE-2026-81240 | Sep 15, 2026 |
Dell Wyse MS Unrestricted File Upload RCE (Before 2605.0.3.683)Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution. |
|
| CVE-2026-81239 | Sep 15, 2026 |
Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type vulnerabilityDell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution. |
|
| CVE-2026-81236 | Sep 15, 2026 |
Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type vulnerabilityDell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution. |
|
| CVE-2026-63696 | Sep 15, 2026 |
Dell SmartFabric OS10 <10.6.1.3: DCOIC Remote Code ExecDell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Download of Code Without Integrity Check vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution. |
|
| CVE-2026-63695 | Sep 15, 2026 |
Dell SmartFabric OS10 Session Fixation (10.6.1.2)Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Session Fixation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Session theft. |
|
| CVE-2026-81046 | Sep 10, 2026 |
Dell ThinOS 10 <2605_10.2616: Protection Mechanism Failure (Arbitrary Code Exec)Dell ThinOS 10, versions prior to 2605_10.2616, contain a Protection Mechanism Failure vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Arbitrary Code Execution within the application context. |
|
| CVE-2026-81468 | Sep 10, 2026 |
Dell ThinOS 10 OS Command Injection Vulnerability (CVE-2026-81468)Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution. |
|
| CVE-2026-81467 | Sep 10, 2026 |
Dell ThinOS 10 OS Command Injection Vulnerability (CVE-2026-81467)Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Command execution. |
|
| CVE-2026-81049 | Sep 10, 2026 |
Dell ThinOS <2605_10.2616 Missing Int Check AOEDell ThinOS 10, versions prior to 2605_10.2616, contain a Missing Support for Integrity Check vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary code execution. |
|
| CVE-2026-81051 | Sep 10, 2026 |
Dell ThinOS 10 <2605_10.2616: SVN Mutable Bypass via Physical AccessDell ThinOS 10, versions prior to 2605_10.2616, contain a Security Version Number Mutable to Older Versions vulnerability. A low privileged attacker with physical access could potentially exploit this vulnerability, leading to Protection mechanism bypass. |
|
| CVE-2026-81048 | Sep 10, 2026 |
Command Injection in Dell ThinOS 10 before 2605_10.2616Dell ThinOS 10, versions prior to 2605_10.2616, contain an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Remote Code execution |
|
| CVE-2026-81052 | Sep 10, 2026 |
Dell ThinOS 10: Download of Code Without Integrity Check in v<2605_10.2616Dell ThinOS 10, versions prior to 2605_10.2616, contain a Download of Code Without Integrity Check vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to arbitrary code execution. |
|
| CVE-2026-46460 | Sep 09, 2026 |
Dell PowerScale OneFS 9.5-9.15 Incorrect Auth Lets Adjac. Attacker Modify LogsDell PowerScale OneFS, versions 9.5.0.0 through 9.7.1.15, versions 9.8.0.0 through 9.13.1.0, and versions prior to 9.15.0.0, contain an Incorrect Authorization vulnerability. A low privileged adjacent network attacker could potentially exploit this vulnerability, leading to unauthorized modification of system logs. |
|
| CVE-2026-40635 | Sep 09, 2026 |
Dell PowerScale OneFS 9.129.13.1: Insecure Temp FileDell PowerScale OneFS versions 9.12.0.0 through 9.13.1.0 contain an Insecure Temporary File vulnerability. A low privileged remote attacker could potentially exploit this vulnerability, leading to denial of service and information tampering. |
|
| CVE-2026-70425 | Sep 09, 2026 |
Dell PowerScale OneFS 9.5-9.14 Cmd Injection Root PrivilegesDell PowerScale OneFS, Versions 9.5.0.0 through 9.7.1.0, Versions 9.8.0.0 through 9.10.1.0, and Versions 9.11.0.0 through 9.14.0.1, contain a command injection vulnerability. An admin privileged local attacker could potentially exploit this vulnerability, leading to elevation of privileges to root, impacting confidentiality, integrity, and availability. |
|
| CVE-2026-23855 | Sep 09, 2026 |
Dell iDRAC9/10 OS Command Injection pre-7.30.10.50Dell iDRAC9, 14G versions prior to 7.00.00.184, 15G/16G versions prior to 7.30.10.50, and Dell iDRAC10, 17G versions prior to 1.30.30.50, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to command injection. |
|
| CVE-2026-79947 | Sep 09, 2026 |
Dell SCG 5.0 OS Command Injection prior to 5.36.00.16/00Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to script injection. |
|
| CVE-2026-78484 | Sep 09, 2026 |
Dell SCG 5.0 Appliance OS Command Injection <5.36.00.16Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to command execution. |
|
| CVE-2026-79945 | Sep 09, 2026 |
Dell SCG 5.0 Appliance <5.36.00.16 OS Command InjectionDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to command execution. |
|
| CVE-2026-78493 | Sep 09, 2026 |
Dell SCG 5.0 Appliance <5.36.00.16 OS Command InjectionDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to command execution. |
|
| CVE-2026-79735 | Sep 09, 2026 |
Dell SCG 5.0 HardCoded Key Vulnerability (pre5.36.00.16)Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Cryptographic Key vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to information disclosure. |
|
| CVE-2026-79693 | Sep 09, 2026 |
Dell SCG 5.0 Appliance/App Priv Escalation before 5.36.00.16/00Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Least Privilege Violation vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to unauthorized access. |
|
| CVE-2026-79942 | Sep 09, 2026 |
Exec with Unnecessary Privileges in Dell SCG 5.0 Appliance <5.36.00.16Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Execution with Unnecessary Privileges vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to unauthorized access. |
|
| CVE-2026-79944 | Sep 09, 2026 |
Dell SCG 5.0 Appliance/App <5.36.00.16/5.36.00.00 Least Privilege ViolationDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Least Privilege Violation vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to unauthorized access. |
|
| CVE-2026-79946 | Sep 09, 2026 |
Dell SCG 5.0 XSS before 5.36.00.16 (App) Improper NeutralizationDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Alternate XSS Syntax vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to script injection. |
|
| CVE-2026-79741 | Sep 09, 2026 |
Dell SCG 5.0 Appliance/App <5.36 cmd injection vulnerabilityDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to script injection. |
|
| CVE-2026-79689 | Sep 09, 2026 |
OS Command Injection in Dell SCG 5.0 Appliance <5.36.00.16 / App <5.36.00.00Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to script injection. |
|
| CVE-2026-79941 | Sep 09, 2026 |
Dell SCG 5.0 Command Injection Vulnerability < 5.36.00.16 (Appliance)Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to script injection. |
|
| CVE-2026-79690 | Sep 09, 2026 |
Dell SCG 5.0 Improper Cert Validation (pre-5.36.00.16/00)Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access. |
|
| CVE-2026-79736 | Sep 09, 2026 |
Dell SCG 5.0 Appliance Unauth Remote Improper Cert Validation (pre5.36.00.16)Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access. |
|
| CVE-2026-79729 | Sep 09, 2026 |
Dell SCG 5.0 <5.36.00.16: Improper Certificate Validation (ICV) VulnerabilityDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access. |
|
| CVE-2026-79732 | Sep 09, 2026 |
Dell SCG 5.0 Appliance <5.36 Improper Cert ValidationDell Secure Connect Gateway (SCG) 5.0 Appliance, versions prior to 5.36.00.xx, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to protection mechanism bypass. |
|
| CVE-2026-78482 | Sep 09, 2026 |
Dell SCG 5.0 OS Command Injection (pre-5.36.00.16/00)Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to command execution. |
|
| CVE-2026-78483 | Sep 09, 2026 |
Dell SCG 5.0 Improper Cert Validation (pre-5.36.00.16/5.36.00.00)Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to protection mechanism bypass. |
|
| CVE-2026-79731 | Sep 09, 2026 |
Dell SCG 5.0 Appl. <5.36.00.16: Hard-coded Creds (CVE-2026-79731)Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Credentials vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to information exposure. |
|
| CVE-2026-79950 | Sep 09, 2026 |
Dell SCG 5.0 <5.36.00.16 Hardcoded Creds, Remote ExploitDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Credentials vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to information exposure. |
|
| CVE-2026-79740 | Sep 09, 2026 |
Dell SCG 5.0 Appliance/App <5.36.00: Hard-Coded Credentials (Unauth Remote)Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Credentials vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to information exposure. |
|
| CVE-2026-79738 | Sep 09, 2026 |
Dell SCG 5.0 Hard-Coded Credentials Vulnerability before 5.36.00.16Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Credentials vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to information exposure. |
|
| CVE-2026-78486 | Sep 09, 2026 |
Hardcoded Crypto Key in Dell SCG 5.0 (<5.36.00.16)Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Cryptographic Key vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access. |
|
| CVE-2026-79964 | Sep 09, 2026 |
Dell SCG 5.0 Improper Neutralization of Escape Sequences <5.36.00Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Escape, Meta, or Control Sequences vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to launch of phishing attacks. |
|
| CVE-2026-79952 | Sep 09, 2026 |
Dell SCG 5.0 Appliance/APP Improper Output Encoding <5.36.00.16 (remote)Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Encoding or Escaping of Output vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to launch of phishing attacks. |
|
| CVE-2026-79971 | Sep 09, 2026 |
Dell SCG 5.0 Improper Sanitization of Custom Special Characters (pre-5.36.00.16)Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Sanitization of Custom Special Characters vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to script injection. |
|