CVE-2026-67271Disclosure

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Dell PowerStore SDNAS, contains an Out-of-bounds Write vulnerability in SMB/CIFS. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service and remote execution. This is a Critical vulnerability as a remote user could send a specially crafted SMB packet and cause a crash, that is persistent in case automatic restarts are enabled. Additionally, a more sophisticated attacker could use the same vulnerability for remote code execution.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 3d ago at 1 mentions (2026-08-20); latest day: 1
  • 4 total mentions across 4 days

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-08-20: 1Mentions · 2026-08-21: 1Mentions · 2026-08-31: 1Mentions · 2026-09-04: 1Patch / Workaround · 2026-08-31: 1Patch / Workaround · 2026-09-04: 1Technical Details · 2026-08-20: 1Technical Details · 2026-08-21: 1Technical Details · 2026-09-04: 108-2008-2108-3109-04
Signal classification2 categories
Disclosure
250.0%
Patch
250.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-08-201
Disclosure1
2026-08-211
Disclosure1
2026-08-311
Patch1
2026-09-041
Patch1
Full discourse4 posts
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 CRITICAL: CVE-2026-67271 (CVSS 9.8) Dell PowerStore SDNAS out-of-bounds write in SMB/CIFS. Unauthenticated remote attacker can achieve RCE or DoS. Patch immediately. #CVE #Vulnerability #PatchNow #ThreatIntel #DFIR https://t.co/fJAv6NvvIh

    Post summary

    The tweet alerts to CVE-2026-67271, an out‑of‑bounds write in Dell PowerStore SDNAS that allows unauthenticated RCE or DoS, and urges immediate patching.

    0000030
    124 followersView on X
  • NCIIPC India@NCIIPC
    Patch

    #Dell has released security #Updates for #PowerStore family which addresses multiple security vulnerabilities. #CVE-2026-67271 #CVE-2026-58574 https://www.dell.com/support/kbdoc/en-in/000497829/dsa-2026-330-dell-powerstore-t-security-update-for-multiple-vulnerabilities

    Post summary

    Dell issued security updates for PowerStore to address CVE‑2026‑67271 and CVE‑2026‑58574, with a link to the vendor advisory.

    00000305
    8.5K followersView on X
  • キタきつね@foxbook
    Disclosure

    CVE-2026-67271 (CVSS 9.8): Dell PowerStoreにおける認証なしのリモートコード実行の脆弱性 CVE-2026-67271 (CVSS 9.8): Unauth RCE in Dell PowerStore #DailyCyberSecurity (Aug 20) https://securityonline.info/dell-powerstore-vulnerability-cve-2026-67271/

    Post summary

    The post announces an unauthenticated remote code execution vulnerability in Dell PowerStore (CVE‑2026‑67271) with a high CVSS score, but lacks details on exploitation or mitigation.

    00000256
    4.9K followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    Disclosure

    A critical Dell PowerStore vulnerability, CVE-2026-67271 (CVSS 9.8), allows unauthenticated remote code execution via SMB. Two more flaws patched. #DellPowerStore #CVE202667271 #RCE #SMB #Storage #InfoSec https://securityonline.info/dell-powerstore-vulnerability-cve-2026-67271/

    Post summary

    The tweet announces a serious Dell PowerStore vulnerability (CVE-2026-67271) with RCE via SMB, providing technical details but no PoC, exploitation evidence, or patch information.

    00000397
    12.9K followersView on X

Explore more