PatchSiren

Dell CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL Dell CVE published 2026-08-06

CVE-2026-67261

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T15:17:24.430Z and has not been modified since then. Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, are affected by an OS Command Injection vulnerability in the IAPI component. This critical vulnerability allows an unauthenticated remote attacker to achieve [truncated]

CRITICAL Dell CVE published 2026-08-06

CVE-2026-54489

Dell Virtual Storage Integrator for VMware vSphere Client versions prior to 10.11.1.0 contain a Sensitive Information Disclosure vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to information disclosure and session hijacking. This vulnerability is considered critical as it allows an unauthenticated attacker to obtain active session credentials and fu [truncated]

HIGH Dell CVE published 2026-08-03

CVE-2026-59913

Dell Display and Peripheral Manager (DDPM Mac) versions prior to 2.3.0.1005 contain a Missing Authentication for Critical Function vulnerability, allowing low-privileged attackers with local access to potentially elevate privileges. Organizations should apply patches or updates to version 2.3.0.1005 or later, restrict local access to sensitive systems, and monitor for suspicious activity. The vulnerabilit [truncated]

HIGH Dell CVE published 2026-08-03

CVE-2026-59912

Dell Display and Peripheral Manager (DDPM Mac) versions prior to 2.3.0.1005 contain an Improper Access Control vulnerability. A low-privileged attacker with local access could exploit this, leading to elevation of privileges and arbitrary code execution. The vulnerability has a CVSS score of 7.8 and is classified as HIGH severity. Users should prioritize patching to prevent potential elevation of privileg [truncated]

HIGH Dell CVE published 2026-07-22

CVE-2026-49499

CVE-2026-49499 is a Generation of Incorrect Security Tokens vulnerability in Dell PowerProtect Data Manager's IAM. A low-privileged attacker with remote access could exploit this, leading to privilege escalation. The vulnerability exists in the Identity and Access Management (IAM) component of Dell PowerProtect Data Manager. Successful exploitation could allow a low-privileged attacker with remote access [truncated]

CRITICAL Dell CVE published 2026-07-22

CVE-2026-46738

CVE-2026-46738 is a CRITICAL 9.1 vulnerability in Dell PowerProtect Data Manager, a data management solution. A high privileged attacker with remote access could potentially exploit this Improper Input Validation vulnerability in the REST API, leading to Elevation of privileges. This vulnerability affects versions prior to 20.2.0.0. Security teams should review and validate affected scope, severity, and v [truncated]

MEDIUM Dell CVE published 2026-07-22

CVE-2026-46737

CVE-2026-46737 is an Improper Input Validation vulnerability in the REST API of Dell PowerProtect Data Manager versions prior to 20.2.0.0. A high-privileged attacker with remote access could exploit this vulnerability, potentially leading to remote code execution. The vulnerability exists due to inadequate validation of input in the REST API, which could allow an attacker to execute arbitrary code. Admini [truncated]

MEDIUM Dell CVE published 2026-07-22

CVE-2026-44276

A high privileged attacker with local access could potentially exploit this vulnerability in Dell PowerProtect Data Manager, versions prior to 20.2.0.0, leading to Information exposure via the REST API. This vulnerability is classified as an Exposure of Sensitive Information to an Unauthorized Actor. The CVE record and NVD entry provide additional context for this vulnerability.

CRITICAL Dell CVE published 2026-07-22

CVE-2026-40712

CVE-2026-40712 is a CRITICAL 9.1 vulnerability in Dell PowerProtect Data Manager's REST API, allowing high-privileged attackers with remote access to potentially exploit an Improper Input Validation vulnerability, leading to privilege escalation. This vulnerability affects versions prior to 20.2.0.0. Security teams must prioritize patching to prevent potential attacks.

HIGH Dell CVE published 2026-07-15

CVE-2026-56687

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-15T18:16:48.493Z and has not been modified since then. This Obsolete Feature in UI vulnerability affects Dell ThinOS 10, versions prior to 2605_10.2100. A low privileged attacker with local access could potentially exploit this vulnerability, leading to unauthorized access. Security teams should rev [truncated]

MEDIUM Dell CVE published 2026-07-15

CVE-2026-49501

CVE-2026-49501 is an Improper Privilege Management vulnerability affecting Dell PowerScale OneFS versions 9.5.0.0 through 9.10.1.7 and 9.11.0.0 through 9.13.0.2. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. This vulnerability has a CVSS score of 6.7 and a severity of MEDIUM. System administrators and security teams should be [truncated]

MEDIUM Dell CVE published 2026-07-10

CVE-2026-54470

CVE-2026-54470 is an Improper Restriction of XML External Entity Reference vulnerability in Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access. This vulnerability has a CVSS score of 5.3 and a severity of MEDIUM. Security teams should review the CVE record and NVD entry for fu [truncated]

HIGH Dell CVE published 2026-07-10

CVE-2026-54469

A low privileged attacker with remote access could potentially exploit the Deserialization of Untrusted Data vulnerability in Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior, leading to arbitrary command execution with root privileges. This executive overview covers the affected product, vulnerability class, and likely operational impact. The vulnerability has a CVSS score of 8.8 and a severity of HIGH.

HIGH Dell CVE published 2026-07-10

CVE-2026-56690

CVE-2026-56690 is an SQL injection vulnerability in Dell PowerFlex Manager versions prior to 5.1.0.1. A low-privileged attacker with remote access could potentially exploit this vulnerability, leading to information disclosure, information exposure, and unauthorized access. This vulnerability has a CVSS score of 8.5 and a severity rating of HIGH. Organizations should prioritize patching this vulnerability [truncated]

HIGH Dell CVE published 2026-07-10

CVE-2026-56689

CVE-2026-56689 is an SQL injection vulnerability in Dell PowerFlex Manager versions prior to 5.1.0.1. A low-privileged attacker with remote access could potentially exploit this vulnerability, leading to information exposure. The vulnerability has a CVSS score of 7.7 and a CVSS severity of HIGH. The CVE record was published on 2026-07-10T12:17:23.577Z and has not been modified since then.

MEDIUM Dell CVE published 2026-07-10

CVE-2026-54468

A low privileged attacker with remote access could potentially exploit the path traversal vulnerability in Dell Unisphere for PowerMax, versions 10.3.0.5 and prior, to read arbitrary files. This vulnerability has a CVSS score of 6.5 and a severity rating of MEDIUM. Security teams and administrators responsible for Dell Unisphere for PowerMax systems should review and apply necessary patches. The vulnerabi [truncated]

HIGH Dell CVE published 2026-07-08

CVE-2026-56086

CVE-2026-56086 is an Incorrect Authorization vulnerability in Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access. The vulne [truncated]

HIGH Dell CVE published 2026-07-08

CVE-2026-53482

CVE-2026-53482 describes an Integer overflow or wraparound vulnerability in Dell PowerProtect Data Domain versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, and LTS2024 release versions 7.13.1.0 through 7.13.1.70. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of s [truncated]

LOW Dell CVE published 2026-07-08

CVE-2026-53480

CVE-2026-53480 is a path traversal vulnerability in Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized file modification. The vulnerability has a CVSS score of 2.7 and a CVSS severity of LOW. System administrators and security teams should be aware of this vulnerability and take ne [truncated]

HIGH Dell CVE published 2026-07-08

CVE-2026-41122

CVE-2026-41122 is a stored cross-site scripting vulnerability in Dell PowerProtect Data Domain. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to information disclosure, session theft, or client-side request forgery. The vulnerability affects multiple versions of Dell PowerProtect Data Domain, including versions 7.7.1.0 through 8.7, LTS2026 release ver [truncated]

HIGH Dell CVE published 2026-07-07

CVE-2026-53479

CVE-2026-53479 is an OS command injection vulnerability in Dell PowerProtect Data Domain. A remote high privileged attacker could exploit this vulnerability, leading to protection mechanism bypass. The vulnerability affects Dell PowerProtect Data Domain versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, and LTS2024 release vers [truncated]

CRITICAL Dell CVE published 2026-07-07

CVE-2026-53483

CVE-2026-53483 is a critical severity vulnerability in Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access. The vulnerabil [truncated]

CRITICAL Dell CVE published 2026-07-07

CVE-2026-53481

CVE-2026-53481 is a critical severity Path Traversal vulnerability in Dell PowerProtect Data Domain. An unauthenticated attacker with remote access could exploit this vulnerability, leading to unauthorized access to the system. The vulnerability affects Dell PowerProtect Data Domain versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3. [truncated]

HIGH Dell CVE published 2026-07-03

CVE-2026-53478

CVE-2026-53478 is an OS command injection vulnerability in Dell PowerProtect Data Domain. A high-privileged attacker with remote access could exploit this vulnerability, leading to command execution. The vulnerability affects multiple versions of Dell PowerProtect Data Domain, including versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through [truncated]

HIGH Dell CVE published 2026-07-03

CVE-2026-49815

CVE-2026-49815 is an OS command injection vulnerability in Dell PowerProtect Data Domain. A high-privileged attacker with remote access could exploit this vulnerability, leading to execution of arbitrary OS commands. The vulnerability affects Dell PowerProtect Data Domain versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, and L [truncated]

HIGH Dell CVE published 2026-07-03

CVE-2026-49814

CVE-2026-49814 is an OS Command Injection vulnerability in Dell PowerProtect Data Domain. A high-privileged attacker with remote access could exploit this vulnerability, leading to arbitrary command execution. This vulnerability affects Dell PowerProtect Data Domain versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 rel [truncated]

MEDIUM Dell CVE published 2026-07-03

CVE-2026-49813

CVE-2026-49813 is an OS command injection vulnerability in Dell PowerProtect Data Domain. A high-privileged attacker with local access could exploit this vulnerability, leading to arbitrary command execution. The vulnerability affects Dell PowerProtect Data Domain versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 relea [truncated]

LOW Dell CVE published 2026-07-03

CVE-2026-46466

A high privileged attacker with remote access could potentially exploit this vulnerability in Dell PowerProtect Data Domain, leading to information tampering. The vulnerability affects Dell PowerProtect Data Domain versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, and LTS2024 release versions 7.13.1.0 through 7.13.1.70. This i [truncated]

MEDIUM Dell CVE published 2026-07-03

CVE-2026-46465

A high privileged attacker with remote access could potentially exploit the use of externally-controlled format string vulnerability in Dell PowerProtect Data Domain, leading to Information disclosure and denial of service. The vulnerability affects Dell PowerProtect Data Domain versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30 [truncated]

MEDIUM Dell CVE published 2026-07-03

CVE-2026-46464

A high privileged attacker with remote access could potentially exploit the improper link resolution before file access vulnerability in Dell PowerProtect Data Domain, leading to information disclosure. This vulnerability exists in versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, and LTS2024 release versions 7.13.1.0 through [truncated]

MEDIUM Dell CVE published 2026-07-03

CVE-2026-46463

CVE-2026-46463: Dell PowerProtect Data Domain Vulnerability Debrief. Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, and LTS2024 release versions 7.13.1.0 through 7.13.1.70, contain an integer overflow or wraparound vulnerability. An unauthenticated attacker with remote access could potentially [truncated]

LOW Dell CVE published 2026-07-03

CVE-2026-56085

A low privileged attacker with local access could potentially exploit the use of uninitialized resource vulnerability in Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70, leading to information exposure. This vulnerability is caused by the use [truncated]

MEDIUM Dell CVE published 2026-07-03

CVE-2026-54483

CVE-2026-54483 is an OS command injection vulnerability in Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70. A high privileged attacker with local access could potentially exploit this vulnerability, leading to command execution. The vulnerabil [truncated]

MEDIUM Dell CVE published 2026-07-03

CVE-2026-46730

CVE-2026-46730 is an incorrect authorization vulnerability in Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70. A high privileged attacker with local access could potentially exploit this vulnerability, leading to unauthorized command execution.

MEDIUM Dell CVE published 2026-07-03

CVE-2026-46468

A high privileged attacker with local access could potentially exploit the link following vulnerability in Dell PowerProtect Data Domain, leading to information exposure. This vulnerability affects Dell PowerProtect Data Domain systems, particularly versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, and LTS2024 release versions [truncated]

MEDIUM Dell CVE published 2026-07-03

CVE-2026-46467

A low privileged attacker with local access could potentially exploit this vulnerability in Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70, leading to information exposure. This vulnerability is an insertion of sensitive information into log [truncated]

MEDIUM Dell CVE published 2026-07-03

CVE-2026-44269

A high privileged attacker with local access could potentially exploit this improper link resolution before file access ('link following') vulnerability in Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70, leading to unauthorized access. The vu [truncated]

MEDIUM Dell CVE published 2026-07-03

CVE-2026-44268

CVE-2026-44268 is an incorrect permission assignment for a critical resource vulnerability in Dell PowerProtect Data Domain. A high-privileged attacker with local access could potentially exploit this vulnerability, leading to unauthorized access. The vulnerability exists in multiple versions of Dell PowerProtect Data Domain, including versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through [truncated]

LOW Dell CVE published 2026-07-03

CVE-2026-41124

A high privileged attacker with local access could potentially exploit the path traversal vulnerability in Dell PowerProtect Data Domain, leading to information exposure. The vulnerability affects Dell PowerProtect Data Domain versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, and LTS2024 release versions 7.13.1.0 through 7.13. [truncated]

MEDIUM Dell CVE published 2026-07-03

CVE-2026-41123

A low privileged attacker with remote access could potentially exploit the improper access control vulnerability in Dell PowerProtect Data Domain, leading to information tampering. This vulnerability affects multiple versions of Dell PowerProtect Data Domain and has a CVSS score of 4.3, indicating a medium severity. The vulnerability is related to an improper access control in the RBAC. System administrat [truncated]

MEDIUM Dell CVE published 2026-07-03

CVE-2026-26355

CVE-2026-26355 is an OS command injection vulnerability in Dell PowerProtect Data Domain. A high-privileged attacker with remote access could exploit this vulnerability, leading to command execution. The vulnerability affects Dell PowerProtect Data Domain versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versio [truncated]

HIGH Dell CVE published 2026-06-25

CVE-2026-46735

Dell Display and Peripheral Manager (DDPM Mac) versions prior to 2.3 are vulnerable to an OS Command Injection vulnerability. A low-privileged attacker with local access could exploit this vulnerability, potentially leading to command execution. The vulnerability has a high impact due to its local attack vector. Evidence is limited, and defenders should verify affected scope and vendor guidance. Dell Disp [truncated]

HIGH Dell CVE published 2026-06-25

CVE-2026-46733

CVE-2026-46733 is an Improper Access Control vulnerability in Dell Display and Peripheral Manager (DDPM Windows) versions prior to 2.3. A low-privileged attacker with local access could potentially exploit this vulnerability, leading to code execution. The vulnerability has a CVSS score of 7.8 and is classified as HIGH severity. Dell has provided a vendor advisory for mitigation. Users should review and a [truncated]

MEDIUM Dell CVE published 2026-06-22

CVE-2026-44273

CVE-2026-44273 is a Use of Default Credentials vulnerability in Dell Wyse Management Suite (WMS) versions prior to WMS 2605. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information Disclosure. The vulnerability has a CVSS score of 6 and a severity of MEDIUM. Dell has provided a vendor advisory for mitigation. The CVE was published on 2026-06-22T20: [truncated]

HIGH Dell CVE published 2026-06-22

CVE-2026-44272

CVE-2026-44272 is a high-severity SQL injection vulnerability in Dell Wyse Management Suite (WMS) versions prior to WMS 2605. A low-privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access. The vulnerability has a CVSS score of 8.8 and is considered HIGH severity. Dell has provided a vendor advisory for mitigation. The CVE was published on June 22 [truncated]

LOW Dell CVE published 2026-06-17

CVE-2026-35068

CVE-2026-35068 is an SQL injection vulnerability in Dell PowerFlex Manager versions prior to 5.1.0.1. A low-privileged attacker with adjacent network access could exploit it, leading to information disclosure. The vulnerability has a CVSS score of 3.5 and a severity of LOW. Organizations should review and apply patches to prevent potential information disclosure.

HIGH Dell CVE published 2026-06-17

CVE-2026-32652

CVE-2026-32652 is a 'Use of Default Credentials' vulnerability in Dell AIOps Collector versions prior to 1.18.3. A low privileged attacker with console access could potentially exploit this vulnerability to gain Filesystem access. This vulnerability only affects fresh installations of Collector versions earlier than 1.18.3. Systems that have been upgraded to version 1.18.3 or later are not impacted, even [truncated]

MEDIUM Dell CVE published 2026-06-17

CVE-2025-32748

CVE-2025-32748 is a medium-severity vulnerability in Dell PowerFlex rack, versions RCM 3.7/3.7. An unauthenticated attacker with remote access could potentially exploit this Host Header Injection vulnerability to trigger redirections. Organizations using affected versions should review and update their systems to mitigate potential risks. The CVSS score for this vulnerability is 4.3, indicating a medium s [truncated]

HIGH Dell CVE published 2026-06-17

CVE-2026-49502

CVE-2026-49502 is an Improper Authentication vulnerability in Dell PowerFlex Manager versions prior to 5.1.0.1. An unauthenticated attacker with adjacent network access could exploit this vulnerability, leading to information disclosure, tampering, and unauthorized access. The vulnerability has a high CVSS score of 7.4, indicating a high risk. Security teams should review and address this vulnerability promptly.

MEDIUM Dell CVE published 2026-06-17

CVE-2026-40641

CVE-2026-40641 is a Use of a Broken or Risky Cryptographic Algorithm vulnerability in Dell PowerFlex Manager versions prior to 5.1.0.1. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure and Information tampering. The vulnerability has a CVSS score of 4.8 and a severity rating of MEDIUM. The affected product is Dell PowerFlex Mana [truncated]