Update Package Framework Dell Update Package Framework

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Dell Update Package Framework.

By the Year

In 2026 there have been 5 vulnerabilities in Dell Update Package Framework with an average score of 5.6 out of ten. Last year, in 2025 Update Package Framework had 1 security vulnerability published. That is, 4 more vulnerabilities have already been reported in 2026 as compared to last year. Last year, the average CVE base score was greater by 2.20

Year Vulnerabilities Average Score
2026 5 5.60
2025 1 7.80
2024 2 7.20

It may take a day or so for new Update Package Framework vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Dell Update Package Framework Security Vulnerabilities

Dell Update Package Framework, versions prior to 26.07.03, contains a Stack-based Buffer Overflow vulnerability
CVE-2026-86358 6.5 - Medium - September 16, 2026

Dell Update Package Framework, versions prior to 26.07.03, contains a Stack-based Buffer Overflow vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Remote execution.

Stack Overflow

Dell Update Package Framework
CVE-2026-71182 3 - Low - September 16, 2026

Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Filesystem access for attacker.

insecure temporary file

Dell Update Package Framework
CVE-2026-71181 3 - Low - September 16, 2026

Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Filesystem access for attacker.

insecure temporary file

Dell Update Package Framework, versions prior to 26.07.03, contains an Unchecked Return Value vulnerability
CVE-2026-71180 8.2 - High - September 16, 2026

Dell Update Package Framework, versions prior to 26.07.03, contains an Unchecked Return Value vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.

Unchecked Return Value

Dell Update Package Framework
CVE-2026-71179 7.3 - High - September 16, 2026

Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.

Shell injection

Dell UPF LPE CVE-2025-22395 (pre-22.01.02)
CVE-2025-22395 7.8 - High - January 07, 2025

Dell Update Package Framework, versions prior to 22.01.02, contain(s) a Local Privilege Escalation Vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading to the execution of arbitrary remote scripts on the server. Exploitation may lead to a denial of service by an attacker.

Improper Handling of Insufficient Permissions or Privileges

Dell DUP Uncontrolled Search Path pre-4.9.10 RCE as Admin
CVE-2023-39254 7.3 - High - March 01, 2024

Dell Update Package (DUP), Versions prior to 4.9.10 contain an Uncontrolled Search Path vulnerability. A malicious user with local access to the system could potentially exploit this vulnerability to run arbitrary code as admin.

DLL preloading

DUP-fw 4.9.4.36 Windows Junction Write Vulnerability
CVE-2023-32454 7.1 - High - February 06, 2024

DUP framework version 4.9.4.36 and prior contains insecure operation on Windows junction/Mount point vulnerability. A local malicious standard user could exploit the vulnerability to create arbitrary files, leading to denial of service

insecure temporary file

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Dell Update Package Framework or by Dell? Click the Watch button to subscribe.

Dell
Vendor

subscribe