Dell PowerEdge Servers Get a Critical System Fix

· All blog posts

Free Assessment Or call 903-675-5431

25+

Years in Business

85+

Years of Experience

137

Servers Maintained

1,367

Workstations Served
Dell PowerEdge servers with a critical system fix text plate. Photo: Dell Inc., via Wikimedia Commons, CC BY-SA 2.0. Cropped with a text plate added.

Dell published security advisory DSA-2026-324 on October 1, 2026, to fix five vulnerabilities in Dell System Update, the command-line tool that many IT teams use to install BIOS, firmware, and driver updates on PowerEdge servers. Every version of the tool before 2.3.0.0 is affected. The encouraging news is that the fix is ready to install today. BleepingComputer also reports that Dell has not flagged any of the five flaws as actively exploited.

The most serious issue is CVE-2026-86360, a path traversal flaw that Dell rates as critical with a CVSS score of 9.6. Dell says an unauthenticated attacker with remote access could use it to run code with root privileges, which could lead to a complete compromise of the tool and the operating system underneath it. Dell's scoring also notes that the attack depends on some user interaction, which offers a little breathing room but no real reason to wait.

The same advisory corrects four more high-severity problems in Dell System Update. Two of them could let a low-privileged local user gain higher privileges on the server, while a third involves improper certificate validation. The fourth is a second path traversal weakness that requires local access to the machine.

Checking a server is quick, because Dell's user guide shows that the command dsu --version reports the installed version on both Windows Server and Linux. Any server that shows a version below 2.3.0.0 should receive the current package from Dell Support, where Dell lists the update under driver ID J9TK1 with separate Windows and Linux installers. Dell recommends that customers upgrade at the earliest opportunity.

The broader lesson for East Texas businesses is that the tools that keep servers current need updates of their own. Dell also offers iDRAC and OpenManage Enterprise as other ways to deliver firmware, yet this advisory names only Dell System Update. The version check therefore belongs on every PowerEdge server where that tool is installed, including older machines that rarely get attention. Adding updater utilities to the regular patch list keeps a helpful maintenance tool from turning into an unwatched entry point.

Palestine companies that keep PowerEdge servers on site can have each one checked for its Dell System Update version during a Free Assessment, with the tool folded into a steady patch routine afterward. Hourly requests are scheduled within the posted weekday hours, while contract customers are covered around the clock. A call to 903-675-5431 is all it takes to put that review on the calendar.

Photo: Dell PowerEdge servers by Dell Inc., via Wikimedia Commons, CC BY-SA 2.0. Cropped with a text plate added.


Need this handled for your team?

Free Assessment

My I.T. Consultants are Experts in the IT Industry

Certifications and Affiliations