Forwarded from National Cybersecurity Information Sharing and Analysis Center: Cybersecurity Alert NISAC-200-202602-00000093
[Content Description]
Researchers have discovered a vulnerability (CVE-2026-22769) in Dell RecoverPoint for Virtual Machines that allows the use of hard-coded credentials. An unauthenticated remote attacker could use a hard-coded credentials to gain root access to the underlying operating system.
This vulnerability has already been exploited by hackers. Please confirm and patch it as soon as possible.
[Affected Platforms]
RecoverPoint for Virtual Machines versions 5.3 SP4 P1 and earlier, 6.0, 6.0 SP1, 6.0 SP1 P1, 6.0 SP1 P2, 6.0 SP2, 6.0 SP2 P1, 6.0 SP3, and 6.0 SP3 P1.
[Recommended Actions]
An official patch has been released to fix the vulnerability. Please refer to the official instructions for updating. The URL is as follows: https://www.dell.com/support/kbdoc/zh-tw/000426773/dsa-2026-079
[References]
1. https://nvd.nist.gov/vuln/detail/CVE-2026-22769
2. https://www.dell.com/support/kbdoc/zh-tw/000426773/dsa-2026-079