VDB
CVE-2026-22769
CVE-2026-22769
PUBLISHED
KEV
CVSS 10 CRITICAL
Dell RecoverPoint for Virtual Machines, versions prior to 6.0.3.1 HF1, contain a hardcoded credential vulnerability. This is considered critical as an unauthenticated remote attacker with knowledge of the hardcoded credential could potentially exploit this vulnerability leading to unauthorized access to the underlying operating system and root-level persistence. Dell recommends that customers upgrade or apply one of the remediations as soon as possible.
EPSS 22.89% · 96.0th percentile
Risk Scores
CVSS 3.1
10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS Score
22.89%
96.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| dell | recoverpoint_for_virtual_machines | 6.0, 6.0, 6.0 |
| Dell | RecoverPoint for Virtual Machines | *, 5.3 SP4 P1, 6.0, 6.0 SP1, 6.0 SP1 P1, 6.0 SP1 P2, 6.0 SP2, 6.0 SP2 P1, 6.0 SP3, and 6.0 SP3 P1 |
Timeline
- Feb 17, 2026 VulnCheck KEV Exploitation
- Feb 17, 2026 CVE Published
- Feb 17, 2026 PoC Published
- Feb 17, 2026 PoC Published
- Feb 17, 2026 PoC Published
- Feb 17, 2026 PoC Published
- Feb 18, 2026 CISA KEV Added
- Feb 18, 2026 EPSS Score
- Feb 18, 2026 PoC Published
- Feb 18, 2026 PoC Published
- Feb 18, 2026 PoC Published
- Feb 18, 2026 PoC Published
References
- https://www.dell.com/support/kbdoc/en-us/000426773/dsa-2026-079 vendor-advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-22769 url
- https://cloud.google.com/blog/topics/threat-intelligence/unc6201-exploiting-dell-recoverpoint-zero-day third-party-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-22769 advisory