Dell vulnerabilities
33 CVEs tracked
Dell appears in this reporting period primarily due to critical vulnerabilities in PowerProtect Data Manager. Most issues involve Improper Input Validation in the REST API, which could allow a remote high-privileged attacker to escalate privileges (CVE-2026-46738, CVE-2026-40712, CVE-2026-40714). Additionally, an incorrect security token generation flaw in the IAM component (CVE-2026-49499) enables similar elevation for a low-privileged attacker, while CVE-2026-46737 could lead to remote code execution. Defenders must urgently update Dell PowerProtect Data Manager to version 20.2.0.0 and apply patches for RVTools (CVE-2026-64993) and Virtual Storage Integrator (CVE-2026-54489).
Azərbaycanca: Dell, hesabat dövründə əsasən PowerProtect Data Manager məhsulunda kritik zəifliklərlə bağlı görünür. Bu zəifliklərin əksəriyyəti REST API-də düzgün olmayan giriş validasiyası (Improper Input Validation) ilə bağlıdır və uzaqdan yüksək imtiyazlı təcavüzkarın imtiyazların yüksəldilməsinə səbəb ola bilər (CVE-2026-46738, CVE-2026-40712, CVE-2026-40714). Bundan əlavə, IAM komponentindəki səhv təhlükəsizlik tokeni yaradılması (CVE-2026-49499) aşağı imtiyazlı istifadəçi üçün oxşar imkan yaradır, CVE-2026-46737 isə uzaqdan kod icrasına aça bilər. Müdafiəçilər Dell PowerProtect Data Manager-i dərhal 20.2.0.0 versiyasına yeniləməli, həmçinin RVTools (CVE-2026-64993) və Virtual Storage Integrator (CVE-2026-54489) üçün buraxılmış yeniləmələri tətbiq etməlidir.
This vendor's CVEs33
- CVE-2026-70415EPSS 0.70%
- CVE-2026-70412EPSS 0.19%
- CVE-2026-67271EPSS 0.46%
- CVE-2026-66272EPSS 0.25%
- CVE-2026-66271EPSS 0.52%
- CVE-2026-66270EPSS 0.42%
- CVE-2026-64993EPSS 0.14%
- CVE-2026-63702EPSS 0.08%
- CVE-2026-63701EPSS 0.08%
- CVE-2026-63700EPSS 0.09%
- CVE-2026-61407EPSS 0.10%
- CVE-2026-59917EPSS 0.11%
- CVE-2026-59916EPSS 0.11%
- CVE-2026-59915EPSS 0.10%
- CVE-2026-59914EPSS 0.12%
- CVE-2026-59911EPSS 0.11%
- CVE-2026-59910EPSS 0.42%
- CVE-2026-59909EPSS 0.12%
- CVE-2026-56794EPSS 0.30%
- CVE-2026-56793EPSS 0.31%
- CVE-2026-56686EPSS 0.42%
- CVE-2026-56685EPSS 0.48%
- CVE-2026-56090EPSS 0.13%
- CVE-2026-56089EPSS 0.14%
- CVE-2026-54489EPSS 0.47%
- CVE-2026-49500EPSS 0.08%
- CVE-2026-49499EPSS 0.42%
- CVE-2026-46738EPSS 0.34%
- CVE-2026-46737EPSS 0.35%
- CVE-2026-46731EPSS 0.12%
- CVE-2026-44276EPSS 0.11%
- CVE-2026-40714EPSS 0.50%
- CVE-2026-40712EPSS 0.35%
This hub is built from skopnix's own reporting on Dell: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.