Dell Patches Critical ThinOS Vulnerabilities

Published September 10, 2026 CVE-2026-81467

Dell ThinOS 10 has a critical flaw that lets an unauthenticated remote attacker run commands on an affected thin client. No user interaction is required.

Severity
CriticalCVSS 3.1 · 9.8
Fix
Not confirmedLast checked today
Affected versions
before 2605_10.2616
Weakness
CWE-78OS Command Injection
Exploit likelihood
3.8% in 30 daysEPSS, higher than 90% of known flaws
Affects
ThinOS 10
Exploited
Not confirmedNo confirmation recorded
CISA SSVC
No known exploitationAutomatable: yes · Technical impact: total
EU ID
EUVD-2026-75568ENISA vulnerability database

What to do

Check the ThinOS version installed on each Dell thin client and compare it with 2605_10.2616. Versions before 2605_10.2616 are in scope.

Install ThinOS 10 version 2605_10.2616 or later using Dell's ThinOS security advisory.

Technical details

CVE-2026-81467 is an unauthenticated, network-reachable command-injection flaw in Dell ThinOS 10. Its CVSS 3.1 score is 9.8, with high confidentiality, integrity, and availability impact.

Severity breakdown

  • Attack vector Network Requires network access to the vulnerable service
  • Attack complexity Low Low complexity under the assessed conditions
  • Privileges required None Attacker needs no account or login
  • User interaction None No victim action needed
  • Scope Unchanged Impact stays within the same security authority
  • Confidentiality impact High Sensitive data can be exposed with serious impact
  • Integrity impact High Protected data can be changed with serious impact
  • Availability impact High The service can stop or suffer serious disruption
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Open in FIRST.org calculator

References