Dell Dell

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any Dell product.

RSS Feeds for Dell security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in Dell products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by Dell Sorted by Most Security Vulnerabilities since 2018

Dell Powerscale Onefs100 vulnerabilities

Dell Wyse Management Suite62 vulnerabilities

Dell Smartfabric Os1032 vulnerabilities

Dell Unity30 vulnerabilities

Dell Secure Connect Gateway28 vulnerabilities

Dell Bsafe Micro Edition Suite28 vulnerabilities

Dell Powerprotect Data Manager24 vulnerabilities

Dell Command Update23 vulnerabilities

Dell Openmanage Enterprise22 vulnerabilities

Dell Objectscale20 vulnerabilities

Dell Unisphere For Powermax20 vulnerabilities

Dell Alienware Command Center19 vulnerabilities

Dell Bsafe Ssl J19 vulnerabilities

Dell Cloudlink16 vulnerabilities

Dell Supportassist13 vulnerabilities

Dell Elastic Cloud Storage12 vulnerabilities

Dell Networker11 vulnerabilities

Dell Bsafe Crypto J10 vulnerabilities

Dell Insightiq10 vulnerabilities

Dell Networking Os109 vulnerabilities

Dell Appsync8 vulnerabilities

Dell Controlvault38 vulnerabilities

Dell Digital Delivery8 vulnerabilities

Dell Alienware Update7 vulnerabilities

Dell Avamar Server7 vulnerabilities

Dell Repository Manager7 vulnerabilities

Dell Storage Manager7 vulnerabilities

Dell Encryption7 vulnerabilities

Dell Update6 vulnerabilities

Dell Display Manager6 vulnerabilities

Dell Emc Appsync6 vulnerabilities

Dell Thinos6 vulnerabilities

Dell Peripheral Manager6 vulnerabilities

Dell Powerstoreos5 vulnerabilities

Dell Command Monitor5 vulnerabilities

Dell Data Lakehouse5 vulnerabilities

Dell Unisphere 3605 vulnerabilities

Dell Enterprise Sonic Os5 vulnerabilities

Dell Power Manager5 vulnerabilities

Dell Idrac95 vulnerabilities

Dell Common Event Enabler4 vulnerabilities

Dell Powerpath4 vulnerabilities

Known Exploited Dell Vulnerabilities

The following Dell vulnerabilities have been marked by CISA as Known to be Exploited by threat actors.

Title Description Added
Dell RecoverPoint for Virtual Machines (RP4VMs) Use of Hard-coded Credentials Vulnerability Dell RecoverPoint for Virtual Machines (RP4VMs) contains an use of hard-coded credentials vulnerability that could allow an unauthenticated remote attacker to gain unauthorized access to the underlying operating system and root-level persistence.
CVE-2026-22769 Exploit Probability: 13.1%
February 18, 2026
Dell dbutil Driver Insufficient Access Control Vulnerability Dell dbutil driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial-of-service, or information disclosure.
CVE-2021-21551 Exploit Probability: 53.1%
March 31, 2022

2 known exploited Dell vulnerabilities are in the top 5% (95th percentile or greater) of the EPSS exploit probability rankings.

By the Year

In 2026 there have been 274 vulnerabilities in Dell with an average score of 6.6 out of ten. Last year, in 2025 Dell had 204 security vulnerabilities published. That is, 70 more vulnerabilities have already been reported in 2026 as compared to last year. Last year, the average CVE base score was greater by 0.14




Year Vulnerabilities Average Score
2026 274 6.63
2025 204 6.77
2024 219 7.07
2023 168 6.97
2022 129 7.20
2021 139 6.94
2020 35 7.45
2019 54 7.32
2018 57 7.21

It may take a day or so for new Dell vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Dell Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2026-63693 Aug 24, 2026
Dell BIOS Improper Link Resolution (Link Following) Vulnerability Dell Client BIOS contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Arbitrary Write
CVE-2026-61419 Aug 24, 2026
Dell ThinOS 10 Improper Access Control Before 2605_10.2518 Dell ThinOS 10, versions prior to 2605_10.2518, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access.
CVE-2026-53477 Aug 19, 2026
Dell Command Update (DCU) TOCTOU Race Condition EoP in <5.7.1 Dell Command Update (DCU), versions prior to 5.7.1, contain a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.
Command Update
CVE-2026-58564 Aug 19, 2026
Dell Command Update <5.7.1 Default Perms: Low Priv Local FS Access Dell Command Update (DCU), versions prior to 5.7.1, contain an Incorrect Default Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Filesystem access for attacker.
Command Update
CVE-2026-67268 Aug 19, 2026
DCU <5.7.0 XXE Local Privilege Escalation Dell Command Update (DCU), versions prior to 5.7.1, contain an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges and Server-side request forgery.
Command Update
CVE-2026-58565 Aug 19, 2026
Dell Command Update <5.7.1 Missing Auth, Priv Escalation Dell Command Update (DCU), versions prior to 5.7.1, contain a Missing Authorization vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.
Command Update
CVE-2026-67266 Aug 19, 2026
Dell Command Update (DCU) <5.7.1: Incorrect Auth -> Priv Escalation Dell Command Update (DCU), versions prior to 5.7.1, contain an Incorrect Authorization vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
Command Update
CVE-2026-58562 Aug 19, 2026
Dell Command Update (DCU) <5.7.1: Missing Authorization (Unauth) Dell Command Update (DCU), versions prior to 5.7.1, contain a Missing Authorization vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access.
Command Update
CVE-2026-67267 Aug 19, 2026
Dell Command Update <=5.7.1 Local Low Priv Info Disclosure Dell Command Update (DCU), versions prior to 5.7.1, contain an Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.
Command Update
CVE-2026-56797 Aug 19, 2026
Dell Command Update <=5.7.1 TOCTOU EC Privileges Dell Command Update (DCU), versions prior to 5.7.1, a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.
Command Update
CVE-2026-49816 Aug 19, 2026
Dell Command Update <5.7.1 Deserialisation of Untrusted Data v0EoP Dell Command Update (DCU), versions prior to 5.7.1, contain a Deserialization of Untrusted Data vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.
Command Update
CVE-2026-49817 Aug 19, 2026
Dell Command Update <5.7.1 Deserialization Vulnerability Dell Command Update (DCU), versions prior to 5.7.1, contain a Deserialization of Untrusted Data vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.
Command Update
CVE-2026-56796 Aug 19, 2026
Dell DCU <=v5.7.1 Improper Link Resolution -> Priv Escalation Dell Command Update (DCU), versions prior to 5.7.1, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.
Command Update
CVE-2026-23501 Aug 19, 2026
Dell RecoverPoint 6.0.3/6.0.3.1 OS Cmd Injection Dell RecoverPoint for VMs, versions 6.0.3 and 6.0.3.1, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.
Recoverpoint Virtual Machines
CVE-2026-32802 Aug 19, 2026
Dell PowerPath 7.2-8.0 SP1 Improper Privilege mgmt: Local Low-Priv Elevation Dell PowerPath, version 7.2 through to 8.0 SP1, contains an Improper Privilege Management vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
Powerpath
CVE-2026-71176 Aug 19, 2026
Dell OpenManage Enterprise <4.7.0 SQLi Vulnerability (Improper Escape) Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.
Openmanage Enterprise
CVE-2026-54793 Aug 19, 2026
XSS in Dell OpenManage Enterprise <4.7.0 (Improper Input Neutralization) Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.
Openmanage Enterprise
CVE-2026-54794 Aug 19, 2026
Dell OpenManage Enterprise SSRF before 4.7.0 Unauthenticated Graph API Dell OpenManage Enterprise, versions prior to 4.7.0, contains a Server-Side Request Forgery (SSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.
Openmanage Enterprise
CVE-2026-70424 Aug 19, 2026
Dell OpenManage Enterprise 4.6.x Path Traversal Before 4.7.0 Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.
Openmanage Enterprise
CVE-2026-70422 Aug 19, 2026
Dell OpenManage Enterprise <4.7.0: SQL Injection via Script Injection Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection.
Openmanage Enterprise
CVE-2026-70423 Aug 19, 2026
Dell OpenManage Enterprise 4.7.0- Prev, XEE Improper Restriction Exposing Info Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.
Openmanage Enterprise
CVE-2026-56088 Aug 19, 2026
Dell OM Enterprise SQLi before v4.7.0 (Improper Neutralization of Special Elements) Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection.
Openmanage Enterprise
CVE-2026-54795 Aug 19, 2026
Dell OM Enterprise <4.7.0 OS Cmd Inj CVE-2026-54795 Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.
Openmanage Enterprise
CVE-2026-70421 Aug 19, 2026
Dell OpenManage Enterprise Improper Privilege Management (4.6) Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Privilege Management vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.
Openmanage Enterprise
CVE-2026-54796 Aug 19, 2026
Dell OpenManage Enterprise <4.7.0 OS Command Injection (High Privileged Remote) Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.
Openmanage Enterprise
CVE-2026-59915 Aug 18, 2026
Dell Alienware Command Center 6.14.20.0 Least Priv Violation Priv Escalation Dell Alienware Command Center (AWCC), versions prior to 6.14.20.0, contain a Least Privilege Violation vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.
Alienware Command Center
CVE-2026-49500 Aug 18, 2026
Alienware Command Center <=6.14.20.0 Improper Link Following Vulnerability Dell Alienware Command Center (AWCC), versions prior to 6.14.20.0, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Denial of Service and Elevation of Privileges.
Alienware Command Center
CVE-2026-32657 Aug 18, 2026
Dell Systems Symlink Follow PrivEsc (AppSync 4.6.0.0, UCC Edge 3.0.1) Dell AppSync Version 4.6.0.0, Dell Metro Node Version 8.0.0, Dell UCC Edge Version 3.0.1, Dell VxRail Version 8.0.322, Dell PowerMax Version 10.3.0, Dell Unity Version 5.4, Dell PowerFlex Manager Version 4.5.4, Dell PowerFlex Intelligent Catalog Versions 46.377.00 and 46.382.00 and Dell PowerFlex Rack version 4.5.4 and prior versions, contain(s) an UNIX Symbolic Link (Symlink) Following vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
Appsync
Unity
CVE-2026-67262 Aug 18, 2026
Dell PowerStore Missing Auth: LUN Access Bypass Dell PowerStore contains a Missing Authorization vulnerability. An attacker with access to a mapped host could exploit this vulnerability to read from or write to LUNs that the host is not authorized to access, bypassing per-initiator LUN access controls and leading to protection mechanism bypass.
CVE-2026-70415 Aug 18, 2026
Dell PowerStore SDNAS NFS/RPC Buffer Copy Without Size Check RCE/DoS Dell PowerStore SDNAS contains a Buffer Copy without Checking Size of Input vulnerability in the NFS/RPC. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Command execution and Denial of service.
CVE-2026-67271 Aug 18, 2026
Dell PowerStore SDNAS SMB/OOB Write Exploit Enables RCE Dell PowerStore SDNAS, contains an Out-of-bounds Write vulnerability in the SMB/CIFS. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Denial of service and Remote execution. This is a Critical vulnerability as a remote user could send a specially crafted SMB packet and cause a crash, that is persistent in case automatic restarts are enabled. Additionally, a more sophisticated attacker could use the same vulnerability for Remote Code execution.
CVE-2026-61407 Aug 18, 2026
Dell Watchdog Timer Driver <=2.0.0.0 Exposed IOCTL allows PrivEsc Dell Watchdog Timer Driver versions prior to 2.0.0.1 contain an Exposed IOCTL with Insufficient Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Privilege Escalation.
CVE-2026-56089 Aug 17, 2026
Dell ObjectScale <=4.3.0.1 Path Traversal (Info Disclosure) Dell ObjectScale, versions prior to 4.3.0.1, contain(s) a Path Traversal vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.
Objectscale
CVE-2026-59911 Aug 17, 2026
Dell ObjectScale <4.3.0.1 svc_tools: Sensitive Info Logged - InfoDisclosure Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Insertion of Sensitive Information into Log File vulnerability in the svc_tools. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.
Objectscale
CVE-2026-59909 Aug 17, 2026
Dell ObjectScale <4.3.0.1 Path Traversal - Low Privileged Local Access Dell ObjectScale, versions prior to 4.3.0.1, contain(s) a Path Traversal vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information tampering.
Objectscale
CVE-2026-56090 Aug 17, 2026
Dell ObjectScale <4.3.0.1: UncSearchPathElement LPE Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Uncontrolled Search Path Element vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
Objectscale
CVE-2026-56685 Aug 17, 2026
Dell ObjectScale v<4.3.0.1: OS Command Injection via Improper Neutralization Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution.
Objectscale
CVE-2026-59910 Aug 17, 2026
Dell ObjectScale OS Command Injection (pre-4.3.0.1) Priv Esc Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
Objectscale
CVE-2026-56686 Aug 17, 2026
Dell ObjectScale <4.3.0.1 OS Command Injection Privilege Escalation Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
Objectscale
CVE-2026-70412 Aug 17, 2026
Dell iDRAC9/10 < 7.20.30.50/1.20.60.50: Remanent Memory Read (Info Disclosure) Dell iDRAC9, versions prior to 7.20.30.50, and Dell iDRAC10, version prior to 1.20.60.50, contain a Remanent Data Readable after Memory Erase vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.
Idrac9
CVE-2026-63700 Aug 14, 2026
Dell Wyse Management Suite <=2605.0.2 Incorrect Default Permission Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Incorrect Default Permission vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Privilege Escalation.
Wyse Management Suite
CVE-2026-66271 Aug 14, 2026
Dell WMS <2605.0.2: Unrestricted Dangerous File Upload RCE Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Unrestricted Upload of File with Dangerous Type vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote Code Execution.
Wyse Management Suite
CVE-2026-66270 Aug 14, 2026
Dell Wyse Management Suite <2605.0.2 Unrestricted File Upload RCE Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Unrestricted Upload of File with Dangerous Type vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote Code Execution.
Wyse Management Suite
CVE-2026-66272 Aug 14, 2026
Missing Auth in Dell Wyse WMS (pre2605.0.2) Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.
Wyse Management Suite
CVE-2026-63701 Aug 14, 2026
Dell Wyse Management Suite 2605 < 2605.0.2 Improper Deserialization PrivEsc Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Improper Deserialization of Untrusted Data vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Privilege Escalation.
Wyse Management Suite
CVE-2026-63702 Aug 14, 2026
Dell WMS <2605.0.2: Hardcoded Creds Vulnerability Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain a Use of Hard-coded Credentials vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access.
Wyse Management Suite
CVE-2026-46731 Aug 12, 2026
Dell DDPM Windows 2.3.0.17 Auth Bypass Spoofing (EOP) Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain an Authentication Bypass by Spoofing vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges and arbitrary code execution.
CVE-2026-59914 Aug 12, 2026
Auth Bypass in Dell DDPM (<2.3.0.17) allows local elevation Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain an Authentication Bypass by Spoofing vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges and arbitrary code execution.
CVE-2026-59917 Aug 12, 2026
Dell DDPM 2.3.0.17 Improper Access Control PrivEsc (DDPM) Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges and arbitrary code execution.
CVE-2026-59916 Aug 12, 2026
Dell DDPM Improper Access Control Privilege Escalation (pre v2.3.0.17) Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges and arbitrary code execution.
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.