CVE-2026-22769

Critical10.0Published on February 17, 2026

Dell RecoverPoint for Virtual Machines, versions prior to 6.0.3.1 HF1, contain a hardcoded credential vulnerability. This is considered critical as an unauthenticated remote attacker with knowledge of the hardcoded credential could potentially exploit this vulnerability leading to unauthorized access to the underlying operating system and root-level persistence. Dell recommends that customers upgrade or apply one of the remediations as soon as possible.

Actively exploited

  • In the CISA exploited-vulnerabilities catalogue since Feb 18, 2026
  • US federal agencies must remediate it by Feb 21, 2026 (BOD 22-01)
  • Attacked 1 day before the vulnerability was made public

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Source: CISA KEV · Mar 16, 2026 Mar 12, 2026 Mar 12, 2026 Mar 4, 2026 Feb 18, 2026 Feb 17, 2026

CVSS score10.0 / 10CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Weakness type (CWE)CWE-798, CWE-798
Vendorsdell

Affected products

VendorsProductVersions
dellrecoverpoint for virtual machines< 6.0

Related articles

This product uses the NVD API but is not endorsed or certified by the NVD.

CVE database