Critical severity10.0CISA KEVNVD Advisory· Published Feb 17, 2026· Updated Jun 17, 2026
CVE-2026-22769
CVE-2026-22769
Description
Dell RecoverPoint for Virtual Machines, versions prior to 6.0.3.1 HF1, contain a hardcoded credential vulnerability. This is considered critical as an unauthenticated remote attacker with knowledge of the hardcoded credential could potentially exploit this vulnerability leading to unauthorized access to the underlying operating system and root-level persistence. Dell recommends that customers upgrade or apply one of the remediations as soon as possible.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
12cpe:2.3:a:dell:recoverpoint_for_virtual_machines:*:*:*:*:*:*:*:*+ 10 more
- cpe:2.3:a:dell:recoverpoint_for_virtual_machines:*:*:*:*:*:*:*:*range: <6.0
- cpe:2.3:a:dell:recoverpoint_for_virtual_machines:6.0:-:*:*:*:*:*:*
- cpe:2.3:a:dell:recoverpoint_for_virtual_machines:6.0:sp1:*:*:*:*:*:*
- cpe:2.3:a:dell:recoverpoint_for_virtual_machines:6.0:sp1_p1:*:*:*:*:*:*
- cpe:2.3:a:dell:recoverpoint_for_virtual_machines:6.0:sp1_p2:*:*:*:*:*:*
- cpe:2.3:a:dell:recoverpoint_for_virtual_machines:6.0:sp2:*:*:*:*:*:*
- cpe:2.3:a:dell:recoverpoint_for_virtual_machines:6.0:sp2_p1:*:*:*:*:*:*
- cpe:2.3:a:dell:recoverpoint_for_virtual_machines:6.0:sp3:*:*:*:*:*:*
- cpe:2.3:a:dell:recoverpoint_for_virtual_machines:6.0:sp3_p1:*:*:*:*:*:*
- (no CPE)range: <6.0.3.1 HF1
- (no CPE)range: 6.0, 6.0 SP1, 6.0 SP1 P1, 6.0 SP1 P2, 6.0 SP2, 6.0 SP2 P1, 6.0 SP3, and 6.0 SP3 P1
- Range: <6.0.3.1 HF1
Patches
Vulnerability mechanics
References
3- www.dell.com/support/kbdoc/en-us/000426773/dsa-2026-079nvdPatchVendor Advisory
- cloud.google.com/blog/topics/threat-intelligence/unc6201-exploiting-dell-recoverpoint-zero-daynvdThird Party Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
2- VerdantBamboo Deploys BSD Variant of BRICKSTORM on Linux AppliancesThe Hacker News · Jun 8, 2026
- vSphere and BRICKSTORM Malware: A Defender's GuideMandiant Threat Intelligence · Apr 2, 2026