Dell
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Dell product.
RSS Feeds for Dell security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Dell products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Dell Sorted by Most Security Vulnerabilities since 2018
Known Exploited Dell Vulnerabilities
The following Dell vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.
| Title | Description | Added |
|---|---|---|
| Dell RecoverPoint for Virtual Machines (RP4VMs) Use of Hard-coded Credentials Vulnerability |
Dell RecoverPoint for Virtual Machines (RP4VMs) contains an use of hard-coded credentials vulnerability that could allow an unauthenticated remote attacker to gain unauthorized access to the underlying operating system and root-level persistence. CVE-2026-22769 Exploit Probability: 13.1% |
February 18, 2026 |
| Dell dbutil Driver Insufficient Access Control Vulnerability |
Dell dbutil driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial-of-service, or information disclosure. CVE-2021-21551 Exploit Probability: 79.2% |
March 31, 2022 |
The vulnerability CVE-2021-21551: Dell dbutil Driver Insufficient Access Control Vulnerability is in the top 1% of the currently known exploitable vulnerabilities. The vulnerability CVE-2026-22769: Dell RecoverPoint for Virtual Machines (RP4VMs) Use of Hard-coded Credentials Vulnerability is in the top 5% of the currently known exploitable vulnerabilities.
By the Year
In 2026 there have been 470 vulnerabilities in Dell with an average score of 6.6 out of ten. Last year, in 2025 Dell had 204 security vulnerabilities published. That is, 266 more vulnerabilities have already been reported in 2026 as compared to last year. Last year, the average CVE base score was greater by 0.17
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 470 | 6.60 |
| 2025 | 204 | 6.77 |
| 2024 | 219 | 7.07 |
| 2023 | 168 | 6.97 |
| 2022 | 129 | 7.20 |
| 2021 | 139 | 6.94 |
| 2020 | 35 | 7.45 |
| 2019 | 54 | 7.32 |
| 2018 | 57 | 7.21 |
It may take a day or so for new Dell vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Dell Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-49811 | Sep 21, 2026 |
Dell Command Monitor <10.13.2: Incorrect Permission Assignment (EoP)Dell Command | Monitor (DCM), versions prior to 10.13.2, contain an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges. |
|
| CVE-2026-81469 | Sep 21, 2026 |
Dell Inventory Collector Client pre-15.0.0 Unquoted Search Path CVE-2026-81469Dell Inventory Collector Client, versions prior to 15.0.0, contain an Unquoted Search Path or Element vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution and Elevation of Privileges |
|
| CVE-2026-82165 | Sep 21, 2026 |
Dell Command Integr Suite <=6.7.1 Incorrect Default Perms (Low Priv Local)Dell Command | Integration Suite for System Center, versions prior to 6.7.2, contain an Incorrect Default Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information Disclosure. |
|
| CVE-2026-49810 | Sep 21, 2026 |
Dell Command Powershell Provider <2.10.2: Log Injection Info DisclosureDell Command Powershell Provider (DCPP), versions prior to 2.10.2 contain an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information Disclosure. |
|
| CVE-2026-82163 | Sep 21, 2026 |
Dell Command | Intel vPro OOB Incorrect Default Permissions (4.7.1)Dell Command | Intel vPro Out of Band, versions prior to 4.7.2, contain an Incorrect Default Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information Disclosure. |
|
| CVE-2026-56795 | Sep 17, 2026 |
Dell Server Update Utility <26.07.01: Unctrl Search Path Element local code execDell Server Update Utility, versions prior to 26.07.01, contains an Uncontrolled Search Path Element vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution. |
|
| CVE-2026-26950 | Sep 17, 2026 |
Dell SmartFabric Manager 2.2.1 - Insufficient Data Auth (CVE-2026-26950)Dell SmartFabric Manager, versions prior to 2.2.1, contains an Insufficient Verification of Data Authenticity vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. |
|
| CVE-2026-54471 | Sep 17, 2026 |
Dell SmartFabric Manager <2.2.1 Improper Privilege Handling VulnerabilityDell SmartFabric Manager, versions prior to 2.2.1, contains an Improper Handling of Insufficient Permissions or Privileges vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure. |
|
| CVE-2026-81447 | Sep 17, 2026 |
Dell OM SA Improper Cert Validation before 11.1.0.3Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information disclosure and Information tampering. |
|
| CVE-2026-80356 | Sep 17, 2026 |
Dell OMSA <11.1.0.3 Sensitive Info Exposure to Unauth ActorsDell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Exposure of Sensitive Information to an Unauthorized Actor vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure. |
|
| CVE-2026-81446 | Sep 17, 2026 |
Dell OpenManage Server Administrator <11.1.0.3 SSRF VulnerabilityDell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Server-Side Request Forgery (SSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Server-side request forgery. |
|
| CVE-2026-81445 | Sep 17, 2026 |
Dell OMGA Improper Privilege Mgmt: Priv Escalation (v<11.1.0.3)Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Privilege Management vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. |
|
| CVE-2026-81453 | Sep 17, 2026 |
Dell OpenManage Server Administrator <11.1.0.3 Path Traversal VulnerabilityDell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access for attacker. |
|
| CVE-2026-81443 | Sep 17, 2026 |
Dell OpenManage Server Admin SSRF before 11.1.0.3Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Server-Side Request Forgery (SSRF) vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Server-side request forgery. |
|
| CVE-2026-81442 | Sep 17, 2026 |
Dell OpenManage Server Admin <11.1.0.3 Privilege Escalation CVE-2026-81442Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Privilege Management vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information tampering and Unauthorized access. |
|
| CVE-2026-80355 | Sep 17, 2026 |
Dell OpenManage Server Administrator <11.1.0.3 CSRF Remote ExecDell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Cross-Site Request Forgery (CSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution. |
|
| CVE-2026-81481 | Sep 17, 2026 |
Dell OpenManage Server Administrator <11.1.0.3 Path Traversal VulnerabilityDell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access for attacker. |
|
| CVE-2026-81480 | Sep 17, 2026 |
Dell OpenManage Server Administrator <11.1.0.3 Stack Buffer OverflowDell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Stack-based Buffer Overflow vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution. |
|
| CVE-2026-81441 | Sep 17, 2026 |
Missing Auth in Dell OpenManage SM Admin <11.1.0.3Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Denial of service. |
|
| CVE-2026-81440 | Sep 17, 2026 |
Dell OpenManage Server Admin: Hardcoded Credentials (CVE202681440) <11.1.0.3Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Use of Hard-coded Credentials vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. |
|
| CVE-2026-81479 | Sep 17, 2026 |
Dell OM Server Admin <11.1.0.3: Partial Str Comp leading to DoS (LPA)Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Partial String Comparison vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Denial of service. |
|
| CVE-2026-81478 | Sep 17, 2026 |
Dell OMA Vulnerable Pre-11.1.0.3 Hard-coded Crypto Key (Unauthorized Access)Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Use of Hard-coded Cryptographic Key vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. |
|
| CVE-2026-81477 | Sep 17, 2026 |
Dell OpenManage SA <=11.1.0.3 Remote HeapBFO for Code ExecDell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Heap-based Buffer Overflow vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution. |
|
| CVE-2026-81476 | Sep 17, 2026 |
OS Command Injection in Dell OpenManage SA <11.1.0.3Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution. |
|
| CVE-2026-81475 | Sep 17, 2026 |
Dell OpenManage Server Administrator <11.1.0.3: Missing Auth Remote ExecDell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution. |
|
| CVE-2026-81439 | Sep 17, 2026 |
Dell OpenManage Incorrect Auth < 11.1.0.3 Remote BypassDell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Incorrect Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass. |
|
| CVE-2026-81438 | Sep 17, 2026 |
Use of Broken Crypto in Dell OMA <11.1.0.3 Allows Info DisclosureDell OpenManage Server Administrator, versions prior to 11.1.0.3, contains Use of a Broken or Risky Cryptographic Algorithm vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure. |
|
| CVE-2026-81474 | Sep 17, 2026 |
Dell OMSA < 11.1.0.3: Heap Buffer Overflow -> Priv EscDell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Heap-based Buffer Overflow vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. |
|
| CVE-2026-66269 | Sep 17, 2026 |
Dell OMA Unsafe Reflection before 11.1.0.3Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass. |
|
| CVE-2026-86359 | Sep 16, 2026 |
Dell Repository Manager, versions prior to 3.5.2, contains an Incorrect Default Permissions vulnerabilityDell Repository Manager, versions prior to 3.5.2, contains an Incorrect Default Permissions vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. |
|
| CVE-2026-86358 | Sep 16, 2026 |
Dell Update Package Framework, versions prior to 26.07.03, contains a Stack-based Buffer Overflow vulnerabilityDell Update Package Framework, versions prior to 26.07.03, contains a Stack-based Buffer Overflow vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Remote execution. |
|
| CVE-2026-71182 | Sep 16, 2026 |
Dell Update Package FrameworkDell Update Package Framework, versions prior to 26.07.03, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Filesystem access for attacker. |
|
| CVE-2026-71181 | Sep 16, 2026 |
Dell Update Package FrameworkDell Update Package Framework, versions prior to 26.07.03, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Filesystem access for attacker. |
|
| CVE-2026-71180 | Sep 16, 2026 |
Dell Update Package Framework, versions prior to 26.07.03, contains an Unchecked Return Value vulnerabilityDell Update Package Framework, versions prior to 26.07.03, contains an Unchecked Return Value vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. |
|
| CVE-2026-71179 | Sep 16, 2026 |
Dell Update Package FrameworkDell Update Package Framework, versions prior to 26.07.03, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. |
|
| CVE-2026-70416 | Sep 16, 2026 |
Dell ObjectScale, versions prior to 4.4.0.0, contains a Deserialization of Untrusted Data vulnerabilityDell ObjectScale, versions prior to 4.4.0.0, contains a Deserialization of Untrusted Data vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution. |
|
| CVE-2026-76104 | Sep 16, 2026 |
Dell ObjectScale, versions prior to 4.4.0.0, contains an Incorrect Permission Assignment for Critical Resource vulnerability in the OSDell ObjectScale, versions prior to 4.4.0.0, contains an Incorrect Permission Assignment for Critical Resource vulnerability in the OS. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Denial of service. |
|
| CVE-2026-26947 | Sep 16, 2026 |
Dell ECS versions 3.8.1.0 through 3.8.1.7Dell ECS versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.4.0.0, contains an Improper Privilege Management vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. |
|
| CVE-2025-43936 | Sep 16, 2026 |
Dell ObjectScale, versions prior to ObjectScale 4.4.0.0, contains an Improper Authentication vulnerabilityDell ObjectScale, versions prior to ObjectScale 4.4.0.0, contains an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. |
|
| CVE-2025-36591 | Sep 16, 2026 |
Dell ECS versions 3.8.1.0 through 3.8.1.7Dell ECS versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.4.0.0, contains an Use of a Broken or Risky Cryptographic Algorithm vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure. |
|
| CVE-2026-81237 | Sep 15, 2026 |
Dell Wyse MS Improper Auth (pre-2605.0.3.683)Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. |
|
| CVE-2026-81238 | Sep 15, 2026 |
Dell Wyse Management Suite 2605.0.3.683 Missing Auth RCE VULNDell Wyse Management Suite, versions prior to 2605.0.3.683, contain a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. |
|
| CVE-2026-81235 | Sep 15, 2026 |
Missing Crypto Step in Dell Wyse MS < 2605.0.3.683 Causes Info TamperingDell Wyse Management Suite, versions prior to 2605.0.3.683, contain a Missing Cryptographic Step vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information tampering. |
|
| CVE-2026-81240 | Sep 15, 2026 |
Dell Wyse MS Unrestricted File Upload RCE (Before 2605.0.3.683)Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution. |
|
| CVE-2026-81239 | Sep 15, 2026 |
Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type vulnerabilityDell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution. |
|
| CVE-2026-81236 | Sep 15, 2026 |
Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type vulnerabilityDell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution. |
|
| CVE-2026-63696 | Sep 15, 2026 |
Dell SmartFabric OS10 <10.6.1.3: DCOIC Remote Code ExecDell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Download of Code Without Integrity Check vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution. |
|
| CVE-2026-63695 | Sep 15, 2026 |
Dell SmartFabric OS10 Session Fixation (10.6.1.2)Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Session Fixation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Session theft. |
|
| CVE-2026-81046 | Sep 10, 2026 |
Dell ThinOS 10 <2605_10.2616: Protection Mechanism Failure (Arbitrary Code Exec)Dell ThinOS 10, versions prior to 2605_10.2616, contain a Protection Mechanism Failure vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Arbitrary Code Execution within the application context. |
|
| CVE-2026-81468 | Sep 10, 2026 |
Dell ThinOS 10 OS Command Injection Vulnerability (CVE-2026-81468)Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution. |