Dell Patches Critical ThinOS Vulnerabilities
Dell ThinOS 10 has a critical flaw that lets an unauthenticated remote attacker run commands on an affected thin client. No user interaction is required.
- Severity
- CriticalCVSS 3.1 · 9.8
- Fix
- Not confirmedLast checked today
- Affected versions
- before 2605_10.2616
- Weakness
- CWE-78OS Command Injection
- Exploit likelihood
- 3.8% in 30 daysEPSS, higher than 90% of known flaws
- Affects
- ThinOS 10
- Exploited
- Not confirmedNo confirmation recorded
- CISA SSVC
- No known exploitationAutomatable: yes · Technical impact: total
- EU ID
- EUVD-2026-75568ENISA vulnerability database
What to do
Check the ThinOS version installed on each Dell thin client and compare it with 2605_10.2616. Versions before 2605_10.2616 are in scope.
Install ThinOS 10 version 2605_10.2616 or later using Dell's ThinOS security advisory.
Technical details
CVE-2026-81467 is an unauthenticated, network-reachable command-injection flaw in Dell ThinOS 10. Its CVSS 3.1 score is 9.8, with high confidentiality, integrity, and availability impact.
Severity breakdown
- Attack vector Network Requires network access to the vulnerable service
- Attack complexity Low Low complexity under the assessed conditions
- Privileges required None Attacker needs no account or login
- User interaction None No victim action needed
- Scope Unchanged Impact stays within the same security authority
- Confidentiality impact High Sensitive data can be exposed with serious impact
- Integrity impact High Protected data can be changed with serious impact
- Availability impact High The service can stop or suffer serious disruption
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Open in FIRST.org calculatorReferences
- nvd.nist.gov · CVE-2026-81467 us government resource vdb entry
- cve.org · CVERecord vdb entry
- rapid7.com · CVE-2026-81467 third party advisory technical description
- cvefeed.io · CVE-2026-81467 third party advisory vdb entry
- tenable.com · CVE-2026-81467 third party advisory vdb entry
- cveawg.mitre.org · CVE-2026-81467
- dell.com · dsa-2026-389-security-update-for-dell-thinos-10-for-multiple-vulnerabilities vendor-advisory NVD