PatchSiren

Dell CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Dell CVE published 2026-04-20

CVE-2026-35154

CVE-2026-35154 is a Dell PowerProtect Data Domain vulnerability involving improper privilege management. According to the CVE description, a high-privileged attacker with local access could potentially elevate privileges to perform unauthorized delete operations. The issue was publicly disclosed on 2026-04-20 and later modified on 2026-05-11. The NVD record lists CVSS 3.1 severity as MEDIUM (6.3) with loc [truncated]

Known exploited Dell CVE published 2026-02-18

CVE-2026-22769

CVE-2026-22769 affects Dell RecoverPoint for Virtual Machines (RP4VMs) and is described as a use of hard-coded credentials vulnerability. CISA added it to the Known Exploited Vulnerabilities catalog on 2026-02-18 with a due date of 2026-02-21, so defenders should treat it as an urgent remediation item. The supplied corpus directs organizations to apply Dell’s mitigations, follow applicable CISA BOD 22-01 [truncated]