CVE-2026-22769: critical vulnerability in Dell RecoverPoint for Virtual Machines
Published · Updated
Prioritize patching. It under exploitation confirmed by CISA.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Dell RecoverPoint for Virtual Machines has a hardcoded password built into the software that anyone can find and use to gain full control of the system without needing to log in normally. This is extremely dangerous because attackers can take over the entire server.
CWE-798 hardcoded credential vulnerability in Dell RecoverPoint for Virtual Machines versions <6.0.3.1 HF1 allows unauthenticated remote attackers to achieve unauthorized OS access and root-level persistence by exploiting publicly discoverable embedded credentials. No user interaction required; attack vector is network-accessible.
The full analysis of this CVE is available in Portuguese →
In the same product, most dangerous first.