CVE-2026-22769Active Exploitation(dell / recoverpoint_for_virtual_machines)

CRITICALCVSS 10.0 · CRITICALCISA KEV

Exploitation observed; activity peaked at 91 mentions and remains active

Immediate actions

  • Patch dell recoverpoint_for_virtual_machines systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Dell RecoverPoint for Virtual Machines, versions prior to 6.0.3.1 HF1, contain a hardcoded credential vulnerability. This is considered critical as an unauthenticated remote attacker with knowledge of the hardcoded credential could potentially exploit this vulnerability leading to unauthorized access to the underlying operating system and root-level persistence. Dell recommends that customers upgrade or apply one of the remediations as soon as possible.

8.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-02-21. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-798

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • recoverpoint_for_virtual_machines

Threat summary

  • Active exploitation appears in 143 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 192 mentions across 23 observed days

What's happening

  • Active exploitation reported across 143 signals
  • Exploit tool or code specified in 13 signals
  • PoC mentioned or linked in 5 signals
  • Patch or workaround mentioned in 53 signals
  • Technical details provided in 91 signals
  • General: 21 classified signals
  • Peaked 21d ago at 91 mentions (2026-02-18); latest day: 1
  • 192 total mentions across 23 days

Affected systems

Vendors
Products
recoverpoint_for_virtual_machines

1 version affected across 1 product

Deep dive

Activity timeline192 mentions / 23d
023466891Mentions · 2026-02-17: 10Mentions · 2026-02-18: 91Mentions · 2026-02-19: 41Mentions · 2026-02-20: 8Mentions · 2026-02-22: 3Mentions · 2026-02-23: 7Mentions · 2026-02-24: 5Mentions · 2026-02-25: 4Mentions · 2026-02-26: 2Mentions · 2026-02-27: 3Mentions · 2026-02-28: 1Mentions · 2026-03-03: 1Mentions · 2026-03-04: 1Mentions · 2026-03-05: 1Mentions · 2026-03-18: 1Mentions · 2026-03-19: 1Mentions · 2026-04-15: 2Mentions · 2026-05-08: 3Mentions · 2026-07-05: 1Mentions · 2026-08-13: 2Mentions · 2026-08-26: 1Mentions · 2026-10-01: 2Mentions · 2026-10-06: 1PoC Mentioned / Linked · 2026-02-18: 2PoC Mentioned / Linked · 2026-02-19: 2PoC Mentioned / Linked · 2026-02-27: 1Exploit Tool / Code · 2026-02-17: 1Exploit Tool / Code · 2026-02-18: 6Exploit Tool / Code · 2026-02-19: 4Exploit Tool / Code · 2026-02-27: 1Exploit Tool / Code · 2026-03-18: 1Active Exploitation · 2026-02-17: 5Active Exploitation · 2026-02-18: 76Active Exploitation · 2026-02-19: 32Active Exploitation · 2026-02-20: 7Active Exploitation · 2026-02-22: 3Active Exploitation · 2026-02-23: 3Active Exploitation · 2026-02-24: 4Active Exploitation · 2026-02-25: 2Active Exploitation · 2026-02-26: 1Active Exploitation · 2026-02-27: 1Active Exploitation · 2026-03-03: 1Active Exploitation · 2026-03-04: 1Active Exploitation · 2026-03-05: 1Active Exploitation · 2026-03-18: 1Active Exploitation · 2026-03-19: 1Active Exploitation · 2026-04-15: 2Active Exploitation · 2026-05-08: 1Active Exploitation · 2026-08-13: 1Patch / Workaround · 2026-02-17: 3Patch / Workaround · 2026-02-18: 22Patch / Workaround · 2026-02-19: 15Patch / Workaround · 2026-02-20: 5Patch / Workaround · 2026-02-22: 2Patch / Workaround · 2026-02-23: 3Patch / Workaround · 2026-03-04: 1Patch / Workaround · 2026-03-18: 1Patch / Workaround · 2026-03-19: 1Technical Details · 2026-02-17: 8Technical Details · 2026-02-18: 41Technical Details · 2026-02-19: 20Technical Details · 2026-02-20: 5Technical Details · 2026-02-22: 2Technical Details · 2026-02-23: 3Technical Details · 2026-02-24: 2Technical Details · 2026-02-25: 2Technical Details · 2026-02-26: 1Technical Details · 2026-02-27: 1Technical Details · 2026-03-04: 1Technical Details · 2026-03-18: 1Technical Details · 2026-03-19: 1Technical Details · 2026-05-08: 1Technical Details · 2026-07-05: 1Technical Details · 2026-08-13: 102-1702-1902-2202-2402-2602-2803-0403-1804-1507-0508-2610-06
Signal classification6 categories
Active Exploitation
13571.4%
General
2111.1%
Patch
157.9%
Disclosure
147.4%
Exploit
31.6%
PoC
10.5%
Referenced assets161 URLs
By indicator
Classification over time
DateTotalLabels
2026-02-1710
Active Exploitation5Disclosure3Patch2
2026-02-1891
Active Exploitation74Disclosure4Exploit2General7Patch4
2026-02-1941
Active Exploitation28Disclosure3General4Patch5PoC1
2026-02-208
Active Exploitation6Patch2
2026-02-223
Active Exploitation3
2026-02-237
Active Exploitation3General2Patch2
2026-02-245
Active Exploitation4General1
2026-02-254
Active Exploitation2Disclosure1General1
2026-02-262
Active Exploitation1General1
2026-02-273
Active Exploitation1Disclosure1General1
2026-02-281
General1
2026-03-031
Active Exploitation1
2026-03-041
Active Exploitation1
2026-03-051
Active Exploitation1
2026-03-181
Active Exploitation1
2026-03-191
Active Exploitation1
2026-04-152
Active Exploitation2
2026-05-083
Active Exploitation1Disclosure1General1
2026-07-051
Exploit1
2026-08-132
General2
2026-08-261
Disclosure1
Full discourse20 posts
  • Peter Girnus 🦅@gothburz
    Active Exploitation

    I am a hardcoded credential inside Dell RecoverPoint for Virtual Machines. My vulnerability ID is CVE-2026-22769 I have been here since launch. My CVSS score is 10. Out of 10. Worst possible score. China found me in 2024. Dell found me in 2026. Time from exploitation to patch: 18 months. Time to change a hardcoded credential: minutes. I am inside a backup product. The product you buy to recover from hackers ships with me preinstalled. I am the recovery plan and the reason you need one.

    Post summary

    The text describes CVE-2026-22769 as a hardcoded credential flaw in Dell RecoverPoint for Virtual Machines with a CVSS score of 10, noting that it was discovered by China in 2024, by Dell in 2026, and that exploitation occurred before a patch was released 18 months later.

    173032276236.5K
    103.1K followersView on X
  • Cyber Security News@The_Cyber_News
    Active Exploitation

    🚨 Dell 0-Day Vulnerability Exploited by Hackers Since mid-2024 to Deploy Malware Source: https://cybersecuritynews.com/dell-0-day-vulnerability/ A critical zero-day exploitation campaign targeting Dell RecoverPoint for Virtual Machines. The vulnerability (CVE-2026-22769) stems from a critical oversight in the configuration of the Apache Tomcat Manager within Dell RecoverPoint appliances. The attackers have utilized this flaw to move laterally across networks, maintain persistent access, and deploy a suite of sophisticated malware, including SLAYSTYLE, BRICKSTORM, and a novel backdoor identified as GRIMBOLT. While the initial access vector remains unconfirmed, UNC6201 is known for targeting edge appliances like VPN concentrators to establish its foothold. #cybersecuritynews

    Post summary

    The Dell RecoverPoint vulnerability CVE‑2026‑22769 is actively exploited in the wild since mid‑2024, enabling lateral movement and malware deployment, with technical details of the oversight but no patch or exploit code disclosed.

    5591144357.5K
    47.0K followersView on X
  • Dan Perez@MrDanPerez
    Active Exploitation

    🚨Hot off the Press🚨 🇨🇳 nexus actor, UNC6201 exploiting CVE-2026-22769 to move laterally and deploy SLAYSTYLE, BRICKSTORM and a new novel backdoor, GRIMBOLT 👀 https://cloud.google.com/blog/topics/threat-intelligence/unc6201-exploiting-dell-recoverpoint-zero-day

    Post summary

    UNC6201 is actively exploiting CVE-2026-22769, moving laterally and deploying multiple malicious tools including a new backdoor, demonstrating real‑world use of the vulnerability.

    13821205114.1K
    4.6K followersView on X
  • The Hacker News@TheHackersNews
    Active Exploitation

    🚨 China-linked UNC6201 exploited a CVSS 10.0 (CVE-2026-22769) Dell RecoverPoint zero-day since 2024 using hard-coded credentials. Access led to Tomcat web shells, BRICKSTORM installs, and newer GRIMBOLT backdoors built to evade detection. 🔗 Read → https://thehackernews.com/2026/02/dell-recoverpoint-for-vms-zero-day-cve.html

    Post summary

    The post reports that China‑linked group UNC6201 has actively exploited CVE-2026-22769 in Dell RecoverPoint systems using hard‑coded credentials, enabling web shells and backdoors.

    64421082710.0K
    1.0M followersView on X
  • Rishi@rxerium
    Active Exploitation

    🚨 Mandiant have identified zero-day exploitation of a high-risk vulnerability in Dell RecoverPoint for Virtual Machines, tracked as CVE-2026-22769. RecoverPoint can be detected using this Nuclei template: https://github.com/projectdiscovery/nuclei-templates/pull/15377/changes Very limited exposure to the internet. Dell recommends upgrading to version 6.0.3.1 HF1 or later. Mitigations are also available. Mandiant report: https://cloud.google.com/blog/topics/threat-intelligence/unc6201-exploiting-dell-recoverpoint-zero-day

    Post summary

    Mandiant reports active exploitation of Dell RecoverPoint CVE‑2026‑22769, a zero‑day vulnerability, with Dell advising a patch and offering mitigations.

    113040162.9K
    3.1K followersView on X
  • CISA Cyber@CISACyber
    Active Exploitation

    🛡️ We added GitLab vulnerability CVE-2021-22175 & Dell RecoverPoint for VMs vulnerability CVE-2026-22769 to our Known Exploited Vulnerabilities Catalog. Visit https://go.dhs.gov/Z3Q & apply mitigations to protect your org from cyberattacks. #Cybersecurity #InfoSec https://t.co/1bDhLNMVjG

    Post summary

    The tweet announces that GitLab CVE‑2021‑22175 and Dell RecoverPoint CVE‑2026‑22769 have been added to a known‑exploited vulnerabilities catalog and urges applying mitigations to defend against current attacks.

    12313735.5K
    291.5K followersView on X
  • YogSotho@YogSoth0
    Exploit

    #CVE-2026-22769 - #Dell RecoverPoint #Exploit kit Attack Chain + Authenticate to #Tomcat Manager (TCP/8443 default) with hardcoded admin/admin credentials + Deploy WAR file via PUT /manager/text/deploy?path=/X&update=true + Execute commands as root via deployed JSP #webshell #cybersecurity #cybernews #0days #security #hacking #antisec #infosec

    Post summary

    The post outlines a detailed attack chain to exploit CVE-2026-22769 using Tomcat Manager’s default credentials, deploying a WAR and executing commands as root, but it provides no patches, active exploitation evidence, or falsity claims.

    12043152.2K
    1.9K followersView on X
  • blackorbird@blackorbird
    General

    From BRICKSTORM to GRIMBOLT: UNC6201 Exploiting a Dell RecoverPoint for Virtual Machines Zero-Day CVE-2026-22769 Dell RecoverPoint for Virtual Machines https://cloud.google.com/blog/topics/threat-intelligence/unc6201-exploiting-dell-recoverpoint-zero-day/ https://t.co/yI1fBflfAy

    Post summary

    The text references a new zero‑day CVE for Dell RecoverPoint for Virtual Machines and links to a blog post, but contains no concrete evidence of an exploit, PoC, patch, or technical details.

    1401161.9K
    39.8K followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(2/18追加) 🛡️No.1524 CVE-2021-22175 GitLab Server-Side Request Forgery (SSRF) Vulnerability ============= CVSSスコア: 6.8 (Base) / GitLab Inc. CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N 種別:サーバサイドのリクエストフォージェリ (CWE-918 / GitLab Inc.) 深刻度:注意 ---------------------- 悪用時影響: 事前認証されてない攻撃者により、Webhook の内部ネットワークへのリクエストが有効になっている場合、サーバーサイドリクエスト フォージェリ (SSRF) の脆弱性の影響を受ける恐れがあります。 https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22175.json 🛡️No.1525 CVE-2026-22769 Dell RecoverPoint for Virtual Machines (RP4VMs) Use of Hard-coded Credentials Vulnerability ============= CVSSスコア: 10.0 (Base) / Dell CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H 種別:ハードコードされた認証情報の使用 (CWE-798 / Dell) 深刻度:緊急🔥 ---------------------- 悪用時影響: 事前認証されていない攻撃者により、リモートからOSおよび特権レベルで永続的に不正なアクセスが行われる恐れがあります。 https://www.dell.com/support/kbdoc/en-us/000426773/dsa-2026-079 https://www.dell.com/support/kbdoc/en-us/000426742/recoverpoint-for-vms-apply-the-remediation-script-for-dsa https://cloud.google.com/blog/topics/threat-intelligence/unc6201-exploiting-dell-recoverpoint-zero-day CISA Adds Two Known Exploited Vulnerabilities to Catalog | CISA https://www.cisa.gov/news-events/alerts/2026/02/18/cisa-adds-two-known-exploited-vulnerabilities-catalog #vulnerability

    Post summary

    CISA confirmed active exploitation of CVE‑2021‑22175 and CVE‑2026‑22769, providing technical details and vendor mitigation steps.

    0401524.3K
    42.5K followersView on X
  • Cyber_OSINT@Cyber_O51NT
    Active Exploitation

    GTIG and Mandiant reveal UNC6201 exploited CVE-2026-22769 in Dell RecoverPoint for Virtual Machines since mid-2024, deploying BRICKSTORM then GRIMBOLT (a native AOT C# backdoor) to pivot into VMware and persist via a boot-time rc.local script. #cybersecu… https://cloud.google.com/blog/topics/threat-intelligence/unc6201-exploiting-dell-recoverpoint-zero-day/

    Post summary

    UNC6201 has actively exploited CVE-2026-22769 in Dell RecoverPoint since mid‑2024, deploying BRICKSTORM and GRIMBOLT backdoors to pivot into VMware and maintain persistence, evidencing real‑world attacks.

    01084789
    21.3K followersView on X
  • IT-Connect.fr@ITConnect_fr
    Active Exploitation

    🛑 𝗗𝗲𝗹𝗹 - 𝗖𝗩𝗘-𝟮𝟬𝟮𝟲-𝟮𝟮𝟳𝟲𝟵 Cette faille critique dans Dell RecoverPoint est exploitée depuis mi-2024 Tous les détails sur IT-Connect 👇 - https://www.it-connect.fr/dell-recoverpoint-faille-critique-cve-2026-22769/ #Dell #infosec #vmware #cybersecurite #virtualisation https://t.co/P5ZttlYGLU

    Post summary

    The tweet announces that Dell RecoverPoint CVE-2026-22769 is being actively exploited since mid‑2024, with no mention of patches or PoC details.

    05032569
    10.9K followersView on X
  • Gray Hats@the_yellow_fall
    Active Exploitation

    Mandiant reveals UNC6201 exploiting Dell RecoverPoint zero-day CVE-2026-22769. Attackers use "Ghost NICs" & GRIMBOLT malware. Patch now. #Dell #ZeroDay #UNC6201 #CyberSecurity #InfoSec #Virtualization #Malware #GRIMBOLT https://securityonline.info/ghost-nics-secret-knocks-dell-zero-day-cvss-10-exploited-by-unc6201/

    Post summary

    Mandiant reports UNC6201 actively exploiting Dell RecoverPoint’s zero‑day CVE‑2026‑22769, with attackers using Ghost NICs and GRIMBOLT malware; a patch has been released.

    22051442
    10.3K followersView on X
  • のらねこ!中華パーツ自作PC本頒布中@ragemax
    Active Exploitation

    中国関連ハッカー、Dell製品のゼロデイを2024年半ばから悪用:CVE-2026-22769 | Codebook|Security News https://codebook.machinarecord.com/threatreport/silobreaker-cyber-alert/43921/

    Post summary

    Chinese‑linked hackers are reportedly exploiting Dell’s CVE‑2026‑22769 starting mid‑2024, with no PoC, patch, or technical details disclosed.

    13130599
    5.9K followersView on X
  • タモ<ハザードマップを確認しましょう>💉x5@tamosan
    Active Exploitation

    『CVE-2026-22769』CVSSv3.1で10.0『リモートより同製品のOSに対して、永続的にroot権限によるアクセスが可能になる』:【セキュリティ ニュース】DellのVM環境向け復旧製品にゼロデイ脆弱性 - 悪用報告も(1ページ目 / 全1ページ):Security NEXT https://www.security-next.com/181174

    Post summary

    CVE‑2026‑22769 is a critical zero‑day vulnerability in Dell's VM recovery product that allows remote persistent root access, with reports of active exploitation in the wild.

    02030222
    2.2K followersView on X
  • JustaBreach@justabreach
    Active Exploitation

    🚨 UNC6201 exploiting Dell RecoverPoint zero-day since mid-2024 Google Threat Intelligence confirms active exploitation of CVE-2026-22769 (CVSS 10.0) → hard-coded Tomcat Manager creds → root RCE via malicious WAR upload Advanced TTPs observed: • SLAYSTYLE Java web shell deployment for initial access • Persistence: tampering with /home/kos/kbox/.../convert_hosts.sh + rc.local to load BRICKSTORM / GRIMBOLT at boot • VMware lateral movement: Ghost NICs (temp interfaces for stealth pivot) + iptables SPA proxying (single-packet auth on 443 → conditional 10443 redirect for 300s) New tool: GRIMBOLT (C# AOT-compiled + UPX-packed backdoor, shared C2 with BRICKSTORM variants) IOCs available (VirusTotal collection via GTIG): C2 149.248.11.71, multiple ELF/SHA256 hashes, YARA rules for hunting Likely targets: critical virtualized envs (ESXi hosts, backups, data protection) Patch available – Dell DSA-2026-338. Apply ASAP + hunt Tomcat /manager accesses in logs (/home/kos/auditlog/fapi_cl_audit_log.log)

    Post summary

    The message reports confirmed active exploitation of CVE-2026-22769 with a zero‑day root RCE, details a malicious WAR upload method, provides an exploit tool (GRIMBOLT), and urges immediate patching via Dell DSA-2026-338.

    01021476
    2.1K followersView on X
  • Cyber News Live@cybernewslive
    Active Exploitation

    Chinese government-backed hackers, known as UNC6201 and Silk Typhoon, are exploiting a critical Dell RecoverPoint vulnerability (CVE-2026-22769) to gain long-term access to networks. This advanced espionage campaign has been active for over a year, using sophisticated malware like Grimbolt. While Dell has released a patch, you should keep your systems updated and many organizations may still be compromised. ⚠️ #CyberNewsLive https://cyberscoop.com/china-brickstorm-grimbolt-dell-zero-day/

    Post summary

    The article reports that Chinese state‑backed actors UNC6201 and Silk Typhoon are actively exploiting CVE‑2026‑22769 in Dell RecoverPoint, using Grimbolt malware, and that a patch is available but many systems may still be compromised.

    02010112
    1.5K followersView on X
  • Misbar | مسبار@MisbarSec
    Active Exploitation

    🚨 ثغرة Dell Zero-day يتم استغلالها من منتصف 2024 مجموعة هاكرز مرتبطة بالصين استغلت ثغرة (CVE-2026-22769) حرجة في برنامج Dell's RecoverPoint for Virtual Machines. الهجمات بدأت منذ منتصف 2024 والهدف هو التجسس الإلكتروني. هذا يؤثر على قدرة المؤسسات على حماية واستعادة بياناتها الافتراضية. 💡 خطوات الحماية: * تحديث برنامج Dell RecoverPoint فور توفر patch. * مراقبة حركة الشبكة بحثًا عن أي نشاط مشبوه. * تطبيق سياسات وصول صارمة للمستخدمين. 🔗 https://www.helpnetsecurity.com/2026/02/18/exploited-dell-zero-day-cve-2026-22769-brickstorm-grimbolt/ #الأمن_السيبراني #Dell #ZeroDay #CyberEspionage

    Post summary

    CVE-2026-22769, a critical Dell RecoverPoint zero‑day, is actively being exploited by Chinese‑affiliated hackers since mid‑2024, prompting urgent patching and monitoring.

    00120291
    50 followersView on X
  • Minery Report@MineryReport
    Active Exploitation

    Alerta Crítica: UNC6201 explota Zero-Day en Dell RecoverPoint (CVE-2026-22769) 🚨⚙️ Un informe de Google Threat Intelligence y Mandiant publicado el 17 de febrero de 2026 revela que el actor avanzado UNC6201 ha estado explotando una vulnerabilidad zero-day en Dell RecoverPoint para Máquinas Virtuales (RP4VM). Lo más preocupante es que el análisis indica acceso silencioso desde mediados de 2024, operando bajo el radar casi dos años. 🟡 Claves del ataque de UNC6201: - La Vulnerabilidad (CVE-2026-22769): Con puntuación 10/10 (Crítica), permite a un atacante remoto no autenticado obtener privilegios root en el appliance. - Método de Intrusión: El atacante localiza credenciales en archivos de configuración (server-xml.xml), accede al Tomcat Manager, sube un archivo malicioso (WAR) y toma control total. 🟡 Nuevos Backdoors: - BRICKSTORM: Modifica scripts legítimos (convert_hosts.sh) para ejecutarse en cada arranque. - GRIMBOLT: Herramienta de persistencia que facilita movimiento lateral en la infraestructura virtual. - “Ghost NICs”: Técnica detectada en ESXi donde se crean puertos de red temporales en VMs para pivotar hacia infraestructuras internas o SaaS sin dejar rastro en logs tradicionales. 🟡 ¿Por qué es tan peligroso? RecoverPoint es una solución de recuperación ante desastres. Si se compromete, los atacantes pueden sabotear la restauración tras ransomware, dejando a la organización sin capacidad de recuperación. ⚠️ Recomendaciones urgentes para el CISO: - Parche inmediato: Seguir la guía oficial de Dell para la CVE-2026-22769. - Threat Hunting: * Revisar /home/kos/auditlog/fapi_cl_audit_log.log en busca de accesos a /manager. * Buscar archivos WAR inusuales en /var/lib/tomcat9. Verificar integridad de /etc/rc.local y convert_hosts.sh. - Auditoría ESXi: Identificar NICs no estándar en vSphere que puedan ser “puertos fantasma”. ⚠️ Mensaje a directivos: Incluso las herramientas de recuperación pueden convertirse en el punto de entrada. En 2026, la monitorización debe incluir también el software que protege vuestra infraestructura. #DellRecoverPoint #UNC6201 #ZeroDay #Mandiant #Ciberseguridad #CVE202622769 #InfoSec #ESXi #CyberAttack2026

    Post summary

    The report confirms that UNC6201 has been actively exploiting CVE-2026-22769 in Dell RecoverPoint for over two years, details the exploitation method and associated backdoors, and urges immediate patching and threat hunting.

    0102087
    296 followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: Critical vulnerability (CVE-2026-22769, CVSSv3 10) patched in #Dell RecoverPoint for Virtual Machines. This vulnerability could allow an unauthenticated attacker to gain root-level access and persistent control of the system. #Patch #Patch #Patch

    Post summary

    CVE‑2026‑22769 is a critical vulnerability (CVSSv3 10) that permits unauthenticated attackers to obtain root access on Dell RecoverPoint for Virtual Machines, but the issue has already been patched by the vendor.

    01020241
    7.2K followersView on X
  • CyberSecurity88@CSec88
    Active Exploitation

    Critical Alert: CVE-2026-22769 Exploited in Dell RecoverPoint for VMs A critical zero-day. Exploited silently since mid-2024. #dell #CyberSecurity Full Story 👉 https://cybersecurity88.com/news/dell-recoverpoint-for-vms-zero-day-cve-2026-22769-actively-exploited-since-mid-2024/ https://t.co/FUJzOLjcOu

    Post summary

    The message states that CVE‑2026‑22769, a zero‑day affecting Dell RecoverPoint for VMs, has been actively exploited silently since mid‑2024.

    00030114
    509 followersView on X
CPE platform detail9 entries

9 of 9 entries

PartVendorProductVersionTarget SWTarget HW
Appdellrecoverpoint_for_virtual_machines---
Appdellrecoverpoint_for_virtual_machines6.0--
Appdellrecoverpoint_for_virtual_machines6.0--
Appdellrecoverpoint_for_virtual_machines6.0--
Appdellrecoverpoint_for_virtual_machines6.0--
Appdellrecoverpoint_for_virtual_machines6.0--
Appdellrecoverpoint_for_virtual_machines6.0--
Appdellrecoverpoint_for_virtual_machines6.0--
Appdellrecoverpoint_for_virtual_machines6.0--

Explore more