VORANT. Threat Intelligence Sign in Get the full feed

Dell RecoverPoint hardcoded credential under active exploitation

critical vulnerability technologygovernment-nationalfinancial-serviceshealthcare

A hardcoded credential vulnerability in Dell RecoverPoint for Virtual Machines is being actively exploited to gain unauthorized root access.

Dell has disclosed a critical hardcoded credential vulnerability (CVE-2026-22769) in RecoverPoint for Virtual Machines versions prior to 6.0.3.1 HF1. The flaw allows unauthenticated remote attackers with knowledge of the hardcoded credential to gain unauthorized access to the underlying operating system with root-level persistence. Dell has received reports from Google/Mandiant confirming limited active exploitation in the wild.

The vulnerability affects Dell's enterprise-grade replication solution for VMware Virtual Machines, which is used for continuous cyber resilience and point-in-time recovery in on-premises environments. Successful exploitation enables arbitrary code execution in the context of the logged-on user, potentially allowing attackers to install programs, modify or delete data, or create new accounts with full administrative rights.

Organizations running affected versions should apply the available hotfix immediately after testing. The vulnerability's active exploitation status and critical severity demand urgent remediation, particularly for government and enterprise users who rely on RecoverPoint for business-critical VM replication and disaster recovery operations.

Mentioned in this report

Vulnerabilities CVE-2026-22769KEV

Source reporting: https://www.cisecurity.org/advisory/a-vulnerability-in-dell-recoverpoint-for-virtual-machines-could-allow-for-arbitrary-code-execution_2026-015

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free