Executive brief
Dell Update Package Framework is a system utility used to deploy firmware and driver updates on Dell hardware. A stack-based buffer overflow in versions before 26.07.03 allows an unauthenticated attacker on the adjacent network to crash the service or potentially execute code remotely, disrupting critical infrastructure updates and potentially compromising system integrity.
Technical details
CVE-2026-86358 is a stack-based buffer overflow vulnerability in Dell Update Package (DUP) Framework prior to version 26.07.03. The vulnerability is triggered by unauthenticated adjacent network access (AV:A), requires no user interaction, and can lead to remote code execution or denial of service. The attack vector is adjacent network, meaning an attacker must be on the same network segment as the affected system. Patch is available in version 26.07.03 and later.
Affected products
- Dell Update Package Framework prior to 26.07.03
Timeline
- 2026-09-16: disclosed