CVE-2026-41120Patch(dell / wyse_management_suite)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch dell wyse_management_suite systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Dell Wyse Management Suite, versions prior to WMS 5.5 HF1, contain an Acceptance of Extraneous Untrusted Data With Trusted Data vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote Code Execution.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-349

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

RISING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • wyse_management_suite

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 5 observed days
  • Momentum state: rising

What's happening

  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 7 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 4 mentions (2026-06-29); latest day: 1
  • 8 total mentions across 5 days

Affected systems

Vendors
Products
wyse_management_suite

1 version affected across 1 product

Deep dive

Activity timeline8 mentions / 5d
01234Mentions · 2026-06-25: 1Mentions · 2026-06-26: 1Mentions · 2026-06-29: 4Mentions · 2026-07-06: 1Mentions · 2026-07-19: 1Patch / Workaround · 2026-06-25: 1Patch / Workaround · 2026-06-29: 4Patch / Workaround · 2026-07-06: 1Technical Details · 2026-06-25: 1Technical Details · 2026-06-29: 4Technical Details · 2026-07-06: 1Technical Details · 2026-07-19: 106-2506-2606-2907-0607-19
Signal classification2 categories
Patch
675.0%
Disclosure
225.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-06-251
Patch1
2026-06-261
Disclosure1
2026-06-294
Patch4
2026-07-061
Patch1
2026-07-191
Disclosure1
Full discourse8 posts
  • Daily CyberSecurity@the_yellow_fall
    Patch

    Critical Dell Wyse vulnerabilities (CVE-2026-41120) allow unauthenticated remote code execution. Administrators must patch management suites immediately. #DellWyse #Vulnerability #CyberSecurity #CVE202641120 #RCE https://securityonline.info/dell-wyse-vulnerabilities-cvss https://t.co/6jFea7rSSe

    Post summary

    Dell Wyse CVE-2026-41120 is a critical unauthenticated remote code execution flaw that requires immediate patching of management suites.

    11010693
    12.4K followersView on X
  • iototsecnews@iototsecnews
    Patch

    Dell Wyse Management の深刻な脆弱性 CVE-2026-41120/49506 が FIX:RCE の恐れ https://iototsecnews.jp/2026/06/29/critical-dell-wyse-management-suite-vulnerabilities-let-attackers-execute-remote-code/ Dell WMS の問題の背景にあるのは、多くの端末を 1 箇所で統括する仕組みの不備です。脆弱性 CVE-2026-41120/CVE-2026-49506 が放置されると、ネットワークの要となる管理基盤が乗っ取られ、配下のすべてのデバイスへと被害が広がる危険性があります。外部からの不正な命令を受け入れたり、本来見られない内部領域を覗かれたりすることで、組織のシステム全体が稼働停止に追い込まれるなど、きわめて深刻な結果を招きます。確実な防衛策として、開発元が提供している最新の修正プログラムを適用し、システムへの経路を制限することが大切です。日頃からアクセス権を最小限に絞り、おかしな挙動がないか見守る体制を整える必要もあります。 #CVE202641120 #CVE202649506 #Dell #Vulnerability #WyseManagement

    Post summary

    The article highlights that Dell Wyse Management Suite has two critical RCE vulnerabilities (CVE-2026-41120 and CVE-2026-49506) and advises applying vendor patches and tightening access controls.

    01000231
    500 followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: Critical vulnerabilities in #Dell #Wyse management suite. CVE-2026-41120 CVSS: 9.8. This #0Day allows remote attackers to remotely execute code #RCE ! More info in our advisory: https://ccb.belgium.be/advisories/warning-critical-vulnerability-dell-wyse-remote-code-execution-remote-low-privileged #Patch #Patch #Patch

    Post summary

    The post announces a critical Dell Wyse RCE vulnerability (CVE‑2026‑41120) with a high CVSS score and directs readers to an advisory that includes a patch or workaround.

    01000391
    7.2K followersView on X
  • IntegSec@integ_sec
    Disclosure

    CVE-2026-41120: Dell Wyse Management Suite Remote Code Execution Bug - What It Means for Your Business and How to Respond https://hubs.li/Q04pZjbr0

    Post summary

    The post announces a newly disclosed CVE (Remote Code Execution in Dell Wyse Management Suite) but offers no details on exploitation, patches, or proof‑of‑concept code – limited context results in low confidence for precise classification.

    0000065
    32 followersView on X
  • TECHEPAGES@techepages
    Patch

    🖥️ Dell patched two critical flaws in Wyse Management Suite: CVE-2026-41120 (CVSS 9.8, no auth needed) and CVE-2026-49506 (CVSS 7.2, path traversal) - both capable of remote code execution on enterprise thin-client systems. 🔧 Fix is live in WMS 5.5 HF1 (released May 8) — patch now, as unpatched/internet-exposed instances face heightened risk.

    Post summary

    Dell issued fixes for two critical remote‑code‑execution vulnerabilities in Wyse Management Suite; immediate patching of WMS 5.5 HF1 is advised to mitigate elevated risk.

    0000099
    21 followersView on X
  • The Daily Tech Feed@dailytechonx
    Patch

    Dell's Wyse Management Suite has critical vulnerabilities (CVE-2026-41120, CVE-2026-49506) allowing remote code execution. Organizations should update to version 5.5 HF1 immediately to mitigate risks to enterprise networks. #Dell #Wyse #CyberSecurity #Vulnerabilities #RemoteCodeExecution #PatchNow https://thedailytechfeed.com/critical-vulnerabilities-in-dell-wyse-management-suite-allow-remote-code-execution/

    Post summary

    The Dell Wyse Management Suite hosts critical remote code execution CVEs (CVE-2026-41120 and CVE-2026-49506), and organizations should apply the 5.5 HF1 patch immediately.

    00000111
    442 followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    We have just added an important vulnerability affecting Dell Wyse Management Suite (CVE-2026-41120) https://vuldb.com/vuln/373835

    Post summary

    The post announces that CVE-2026-41120 has been added to the Vuldb database, without providing details or indicating exploitation or mitigation.

    00000144
    2.2K followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 CRITICAL - Dell Wyse Management Suite extraneous untrusted data injection leads to RCE (CVE-2026-41120) Dell Wyse Management Suite (WMS) versions prior to 5.5 HF1 are vulnerable to Acceptance of Extraneous Untrusted Data With Trusted Data, where attacker-controlled data can be mixed into trusted server-side processing. The root cause is improper input validation / untrusted data injection, allowing extraneous fields or payloads to be accepted and processed as if they were trusted. An attacker with remote access and only low privileges can exploit this by sending crafted requests that smuggle untrusted data into a trusted execution path, resulting in code execution. If exploited, the impact is remote code execution on the WMS server, enabling full compromise of the management plane and downstream control over managed endpoints. 👉 Affected: Dell Wyse Management Suite (WMS) < 5.5 HF1 | Upgrade to WMS 5.5 HF1

    Post summary

    The post announces CVE‑2026‑41120 as a critical remote code execution flaw in Dell Wyse Management Suite, providing mitigation guidance to upgrade to version 5.5 HF1.

    00000105
    228 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appdellwyse_management_suite---
Appdellwyse_management_suite5.5--

Explore more