CVE-2026-40639Disclosure

MEDIUMCVSS 5.7 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Dell Client Platform BIOS contains a Weak Encoding for Password vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Elevation of Privileges.

4.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-261

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 19 mentions across 9 observed days
  • Momentum state: declining

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 17 signals
  • Disclosure: 14 classified signals
  • General: 2 classified signals
  • Peaked 8d ago at 8 mentions (2026-07-10); latest day: 1
  • 19 total mentions across 9 days

Deep dive

Activity timeline19 mentions / 9d
02468Mentions · 2026-07-10: 8Mentions · 2026-07-11: 2Mentions · 2026-07-12: 1Mentions · 2026-07-13: 3Mentions · 2026-07-14: 1Mentions · 2026-07-21: 1Mentions · 2026-07-22: 1Mentions · 2026-09-07: 1Mentions · 2026-09-23: 1PoC Mentioned / Linked · 2026-07-10: 1PoC Mentioned / Linked · 2026-07-13: 1PoC Mentioned / Linked · 2026-09-23: 1Exploit Tool / Code · 2026-07-13: 1Patch / Workaround · 2026-07-10: 1Patch / Workaround · 2026-07-12: 1Patch / Workaround · 2026-07-21: 1Technical Details · 2026-07-10: 6Technical Details · 2026-07-11: 2Technical Details · 2026-07-12: 1Technical Details · 2026-07-13: 3Technical Details · 2026-07-14: 1Technical Details · 2026-07-21: 1Technical Details · 2026-07-22: 1Technical Details · 2026-09-07: 1Technical Details · 2026-09-23: 107-1007-1107-1207-1307-1407-2107-2209-0709-23
Signal classification5 categories
Disclosure
1473.7%
General
210.5%
Exploit
15.3%
Patch
15.3%
PoC
15.3%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-07-108
Disclosure6General2
2026-07-112
Disclosure2
2026-07-121
Disclosure1
2026-07-133
Disclosure2Exploit1
2026-07-141
Disclosure1
2026-07-211
Patch1
2026-07-221
Disclosure1
2026-09-071
Disclosure1
2026-09-231
PoC1
Full discourse19 posts
  • Darren McDonald@R3n5k1
    Disclosure

    New research from @craigsblackie @MDSecLabs and myself @AmberWolfSec . Bug leaks the decryption key for the BIOS password right next to the encrypted password on some Dell platforms. https://blog.amberwolf.com/blog/2026/july/dell-bios-passwords-weak-xor-encryption-allows-recovery-from-spi-flash-cve-2026-40639/

    Post summary

    The blog post announces a Dell BIOS password vulnerability (CVE‑2026‑40639) that leaks the decryption key, enabling password recovery, but it does not include an active exploit or patch information.

    120172397.3K
    155 followersView on X
  • Nicolas Krassas@Dinosn
    Disclosure

    Dell BIOS Passwords: Weak XOR Encryption Allows Recovery from SPI Flash (CVE-2026-40639) https://blog.amberwolf.com/blog/2026/july/dell-bios-passwords-weak-xor-encryption-allows-recovery-from-spi-flash-cve-2026-40639/

    Post summary

    A blog post announces a Dell BIOS password weakness stemming from weak XOR encryption enabling recovery from SPI flash, presenting a disclosure of a new vulnerability.

    0903193.7K
    160.8K followersView on X
  • Swissky@pentest_swissky
    Disclosure

    Dell BIOS Passwords: Weak XOR Encryption Allows Recovery from SPI Flash (CVE-2026-40639) - @R3n5k1 https://blog.amberwolf.com/blog/2026/july/dell-bios-passwords-weak-xor-encryption-allows-recovery-from-spi-flash-cve-2026-40639/

    Post summary

    The blog post announces a new Dell BIOS vulnerability (CVE‑2026‑40639) involving weak XOR encryption that permits password recovery from SPI flash, but it does not provide PoC, exploit code, patch information, or evidence of active exploitation.

    06025132.2K
    23.1K followersView on X
  • MDSec@MDSecLabs
    Disclosure

    Dell BIOS Passwords: Weak XOR Encryption Allows Recovery from SPI Flash (CVE-2026-40639) - new research from @craigsblackie and @R3n5k1 from @AmberWolfSec https://www.mdsec.co.uk/2026/07/dell-bios-passwords-weak-xor-encryption-allows-recovery-from-spi-flash-cve-2026-40639/

    Post summary

    The article announces a newly discovered vulnerability in Dell BIOS—CVE-2026-40639—that leverages weak XOR encryption to recover passwords from SPI flash. No exploit code, active attacks, or patches are discussed.

    01212193.6K
    16.1K followersView on X
  • Nicolas Krassas@Dinosn
    Disclosure

    Dell BIOS Passwords: Weak XOR Encryption Allows Recovery from SPI Flash (CVE-2026-40639) https://www.mdsec.co.uk/2026/07/dell-bios-passwords-weak-xor-encryption-allows-recovery-from-spi-flash-cve-2026-40639/

    Post summary

    CVE-2026-40639 reveals a weakness in Dell BIOS password encryption that permits attackers to recover passwords from SPI Flash memory; the article provides technical details but no PoC, exploit, or patch information.

    24120124.0K
    160.8K followersView on X
  • AmberWolf@AmberWolfSec
    Disclosure

    AmberWolf and @MDSecLabs are jointly disclosing technical details on CVE-2026-40639, a weakness found in how some Dell platforms store BIOS passwords.

    Post summary

    AmberWolf and MDSecLabs jointly disclose technical details that highlight a weakness in Dell BIOS password storage associated with CVE-2026-40639.

    1902543.5K
    552 followersView on X
  • Renaud Lifchitz ⠵@nono2357
    Disclosure

    Dell BIOS Passwords: Weak XOR Encryption Allows Recovery from SPI Flash (CVE-2026-40639) https://blog.amberwolf.com/blog/2026/july/dell-bios-passwords-weak-xor-encryption-allows-recovery-from-spi-flash-cve-2026-40639/

    Post summary

    The blog post announces a Dell BIOS flaw involving weak XOR encryption that allows retrieving passwords from SPI flash, but no exploitation, PoC, patch, or false‑positive claim is present in the provided excerpt.

    04016121.9K
    8.5K followersView on X
  • Craig S. Blackie@craigsblackie
    General

    My next adventure into hacking UEFI, this time with @R3n5k1, my long term friend and fellow hacker! https://www.mdsec.co.uk/2026/07/dell-bios-passwords-weak-xor-encryption-allows-recovery-from-spi-flash-cve-2026-40639/

    Post summary

    The tweet links to an article about CVE-2026-40639, but it does not contain informational or actionable details about exploitation, patches, or confirmation of active use.

    0601573.4K
    478 followersView on X
  • AmberWolf@AmberWolfSec
    General

    You can read the full write up at: https://blog.amberwolf.com/blog/2026/july/dell-bios-passwords-weak-xor-encryption-allows-recovery-from-spi-flash-cve-2026-40639/

    Post summary

    The text merely provides a link to an external blog post about CVE‑2026‑40639, offering no substantive information themselves.

    020821.0K
    552 followersView on X
  • /r/netsec@_r_netsec
    Disclosure

    Dell BIOS Passwords: Weak XOR Encryption Allows Recovery from SPI Flash (CVE-2026-40639) https://blog.amberwolf.com/blog/2026/july/dell-bios-passwords-weak-xor-encryption-allows-recovery-from-spi-flash-cve-2026-40639/

    Post summary

    The blog post announces a BIOS password vulnerability tied to weak XOR encryption, but does not provide evidence of exploitation tools, PoC, or mitigation advice.

    020721.3K
    33.7K followersView on X
  • Mr. OS@ksg93rd
    Exploit

    #exploit 1⃣ Januscape: Guest-to-Host Escape in KVM/x86 (CVE-2026-53359) https://github.com/V4bel/Januscape 2⃣ Dell BIOS Passwords: Weak XOR Encryption Allows Recovery from SPI Flash (CVE-2026-40639) https://blog.amberwolf.com/blog/2026/july/dell-bios-passwords-weak-xor-encryption-allows-recovery-from-spi-flash-cve-2026-40639 ]-> Tooling for extracting and clearing passwords from Dell BIOS flash https://github.com/R3n5k1/dellpwn // http://www.cyberpocket.org

    Post summary

    The tweet showcases functional exploit code and tools for two recent CVEs, providing PoC links and extraction utilities, but does not mention active wild exploitation or available patches.

    01063706
    3.4K followersView on X
  • DFIR Radar@DFIR_Radar
    Disclosure

    CVE-2026-40639: Dell BIOS passwords stored under reversible XOR encryption in SPI flash, recoverable in milliseconds with a chip programmer. Actively unpatched on the Wyse 5070 thin client as of today. Key findings: - Dell's SystemPwSmm SMM driver stores BIOS admin/user passwords as XOR-encrypted data in the DVAR region of SPI flash, not a hash. The first byte is stored in cleartext. For passwords up to 12 characters, null-padding in the 32-byte field leaks the entire 20-byte key directly. No brute force needed. - The key is derived from mostly device-static data plus the cleartext first byte, meaning only 256 possible keys exist per device. DVAR is log-structured, so deleted password records persist on flash. A short historical password with the same first character hands you the key to decrypt a longer current one. - Confirmed vulnerable: Latitude E7250, Latitude 7490, XPS 15 9560, Wyse 5070. Not vulnerable: OptiPlex 3000 and newer models using SIVB with SHA-256. DSA-2026-197 patches Edge Gateway and Precision lines; the Wyse 5070 and confirmed-vulnerable Latitudes are not in that first wave. Dell targets remaining fixes by end of July 2026. - CVSS 3.1 scored 5.7 by Dell (AV:P/AC:H), 6.1 by researchers (AV:P/AC:L). Physical access to flash is required via SOIC clip or attacker-controlled OS boot. Impact: disables Secure Boot, changes boot order, and can break TPM-backed BitLocker chains if unmeasured settings are modified. #DFIR_Radar

    Post summary

    Dell BIOS passwords are stored in XOR‑encrypted form, allowing recovery in milliseconds; the flaw affects several models and remains unpatched, but Dell plans to release fixes by July 2026.

    21052583
    1.9K followersView on X
  • Xeno Kovah@XenoKovah
    PoC

    2026-07-10 "Dell BIOS Passwords: Weak XOR Encryption Allows Recovery from SPI Flash (CVE-2026-40639)" by Craig S. Blackie @craigsblackie et al. Added here: https://darkmentor.com/timeline.html#Dell%20BIOS%20Passwords%3A%20Weak%20XOR%20Encryption%20Allows%20Recovery%20from%20SPI%20Flash%20(CVE-2026-40639):%5B%5BDell%20BIOS%20Passwords%3A%20Weak%20XOR%20Encryption%20Allows%20Recovery%20from%20SPI%20Flash%20(CVE-2026-40639)%5D%5D%20Timeline%20%24%3A%2FTagManager

    Post summary

    The post shares a link to a detailed timeline entry regarding CVE-2026-40639, highlighting a proof of concept or technical method for recovering Dell BIOS passwords from SPI flash due to weak XOR encryption.

    10051256
    13.6K followersView on X
  • iototsecnews@iototsecnews
    Patch

    Dell BIOS の脆弱性 CVE-2026-40639 が FIX:Admin パスワードの復元の恐れ https://iototsecnews.jp/2026/07/11/dell-bios-flaw-lets-attackers-recover-admin-passwords-from-spi-flash-in-milliseconds/ Dell の開発したクライアント・デバイスにおける BIOS 機能ですが、管理者などのパスワードを保存する際、セキュリティ・レベルの低い暗号方式が採用されていたことが判明しました。これにより、物理的にフラッシュ・メモリのデータを読み取られ、OS の管理者権限を奪われた際に、わずか数ミリ秒でパスワードが特定されてしまう危険性があります。この脆弱性 CVE-2026-40639 に対応するためには、利用中の対象機器に対して Dell が提供する最新のファームウェア・アップデートを速やかに適用する必要があります。あわせて、万が一に備え、BIOS パスワードの設定のみに頼るのではなく、OS 側のディスク暗号化や多要素での起動保護を組み合わせる、多層防御が重要になります。 #CVE202640639 #DellBIOS #Vulnerability

    Post summary

    Dell’s BIOS vulnerability CVE-2026-40639 allows rapid admin password recovery from SPI flash; Dell recommends urgent firmware updates and layered security controls.

    02000173
    500 followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    『exact every time for the common case of passwords up to 12 characters, with no brute force and no special conditions.』😨 Dell BIOS Passwords: Weak XOR Encryption Allows Recovery from SPI Flash (CVE-2026-40639) https://blog.amberwolf.com/blog/2026/july/dell-bios-passwords-weak-xor-encryption-allows-recovery-from-spi-flash-cve-2026-40639/

    Post summary

    The blog highlights that Dell BIOS passwords encrypted with weak XOR can be extracted from SPI Flash, exposing CVE-2026-40639.

    01010589
    6.9K followersView on X
  • Dieng2618@Dieng2618
    Disclosure

    Dell BIOS の脆弱性 CVE-2026-40639 が FIX:Admin パスワードの復元の恐れ https://iototsecnews.jp/2026/07/11/dell-bios-flaw-lets-attackers-recover-admin-passwords-from-spi-flash-in-milliseconds/ 数日前から話題になってる問題。 うちのPC(Dell製)、UpdateされたBIOSの公開はまだみたい。

    Post summary

    The text references a Dell BIOS vulnerability (CVE-2026-40639) that allows recovery of admin passwords from SPI flash, but provides no PoC, exploit, or patch information.

    00000105
    630 followersView on X
  • TECHEPAGES@techepages
    Disclosure

    💻 Critical Dell BIOS flaw (CVE-2026-40639) lets attackers recover plaintext passwords from SPI flash in milliseconds. 🔹 Broken XOR scheme leaks the encryption key via null padding — passwords ≤12 chars recovered instantly 🔹 Affects Latitude E7250, XPS 15 9560, Latitude 7490 & the still-supported Wyse 5070 🔹 Physical access required, but no auth or brute force — deterministic recovery 🔹 Biggest risk: bypassing full-disk encryption by disabling Secure Boot/DMA protections; broader Dell fix targeted for end of July 2026

    Post summary

    Dell BIOS bug (CVE‑2026‑40639) allows rapid plaintext password recovery via a broken XOR scheme; a vendor patch is scheduled for end‑July 2026.

    0000085
    19 followersView on X
  • protect_cyber_sec@AmirHossein_sec
    Disclosure

    برای ساختار پسورد BIOS در DELL ، آسیب پذیری با کد شناسایی CVE-2026-40639 منتشر شده است که بدون Bruteforce و در چند میلی‌ ثانیه ، پسورد یوزر administrator و سایر یوزر ها را dump می کند. دیوایس های Dell ای که دارای تنظیمات DVAR و درایور های SMM باشند ، دارای این آسیب پذیری هستند. https://t.co/1WFYJM0Bvs

    Post summary

    A newly published Dell BIOS password dump vulnerability (CVE-2026-40639) can retrieve administrator passwords in milliseconds without brute force, targeting devices with DVAR settings and SMM drivers. No PoC, exploit code, or mitigation details are provided.

    0000082
    205 followersView on X
  • protect_cyber_sec@AmirHossein_sec
    Disclosure

    برای ساختار پسورد BIOS در کلاینت های DELL ، آسیب پذیری با کد شناسایی CVE-2026-40639 منتشر شده است که بدون Bruteforce و در چند میلی‌ ثانیه ، پسورد یوزر administrator و سایر یوزر ها را dump می کند. دیوایس های Dell که دارای تنظیمات DVAR و دارای درایور های SMM باشند ، آسیب پذیر هستند https://t.co/eVFJ9kTzTx

    Post summary

    The text announces a Dell BIOS password‑dumping vulnerability (CVE‑2026‑40639), noting its rapid extraction capability, but it does not provide any PoC, exploit code, or patch information.

    0000077
    205 followersView on X

Explore more