CVE-2026-22769
Dell RecoverPoint for Virtual Machines, versions prior to 6.0.3.1 HF1, contain a hardcoded credential vulnerability. This is considered critical as an unauthenticated remote attacker with knowledge of the hardcoded credential could potentially exploit this vulnerability leading to unauthorized access to the underlying operating system and root-level persistence. Dell recommends that customers upgrade or apply one of the remediations as soon as possible.
Actively exploited
- In the CISA exploited-vulnerabilities catalogue since Feb 18, 2026
- US federal agencies must remediate it by Feb 21, 2026 (BOD 22-01)
- Attacked 1 day before the vulnerability was made public
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Source: CISA KEV · Mar 16, 2026 Mar 12, 2026 Mar 12, 2026 Mar 4, 2026 Feb 18, 2026 Feb 17, 2026
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HAffected products
| Vendors | Product | Versions |
|---|---|---|
| dell | recoverpoint for virtual machines | < 6.0 |
Related articles
This product uses the NVD API but is not endorsed or certified by the NVD.
