Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical Vulnerabilities in Dell ObjectScale Systems Discovered

Critical Vulnerabilities in Dell ObjectScale Systems Discovered

Posted on September 13, 2026 By CWS

Dell Technologies has issued a crucial security advisory concerning several vulnerabilities impacting its ObjectScale and Elastic Cloud Storage (ECS) systems. Among these issues is a severe remote code execution vulnerability that could allow unauthorized users to compromise affected systems. This advisory, labeled DSA-2026-393, was released on September 10, 2026.

Details of the Vulnerabilities

The most critical vulnerability, identified as CVE-2026-70416, involves a deserialization flaw in Dell ObjectScale versions before 4.4.0.0. This vulnerability has been assigned the highest CVSS score of 10.0, indicating its potential to allow remote attackers to execute arbitrary code on unpatched systems.

If exploited successfully, this flaw could provide attackers full control over the ObjectScale environment, granting them the ability to access sensitive data, modify configurations, disrupt operations, deploy harmful software, or maintain a persistent presence within the infrastructure.

Given that ObjectScale is used for enterprise-level object storage, any breach could have profound implications, especially for organizations that use it for storing backups, application data, or cloud-native workloads.

Additional Vulnerabilities and Impact

Another notable vulnerability, CVE-2025-43936, relates to improper authentication and carries a CVSS score of 8.1. This issue affects ObjectScale versions prior to 4.4.0.0 and could allow remote attackers unauthorized access without requiring credentials or user interaction.

Additional vulnerabilities include CVE-2026-26947, an improper privilege management flaw with a CVSS score of 6.7, and CVE-2025-36591, a cryptographic algorithm weakness rated at 4.4. Both vulnerabilities could be exploited by high-privileged local attackers to compromise system confidentiality, integrity, and availability.

CVE-2026-76104, another issue with a CVSS score of 5.5, involves incorrect permission assignments that could enable a denial-of-service attack by high-privileged remote users.

Mitigation and Recommendations

Dell advises affected users to update their ObjectScale and ECS systems to version 4.4.0.0 or later. Those running supported versions may also upgrade to 4.2.0.1. It is recommended to request an Operating Environment Upgrade service and reference the advisory DSA-2026-393.

In the interim, Dell recommends employing Secure Service-Level Communication as outlined in their Security Configuration Guide to mitigate CVE-2025-43936. Security teams are urged to restrict access to administrative interfaces, monitor for unusual activity, and review exposed services.

Dell acknowledged security researcher WinD39, also known as Huynh Dinh Vu, for identifying CVE-2026-70416. Organizations are encouraged to remain vigilant and take immediate action to secure their systems.

Cyber Security News Tags:CVE, Dell, ObjectScale, Security, Vulnerabilities

Post navigation

Previous Post: AI Industry Urged to Prioritize Safety to Prevent Potential Risks

Related Posts

Rise in Phishing Activity Using Spoofed SharePoint Domains With Sneaky2FA Techniques Rise in Phishing Activity Using Spoofed SharePoint Domains With Sneaky2FA Techniques Cyber Security News
Hands-on Cybersecurity Threat Hunting Guide for SOC Analysts and MSSPs Hands-on Cybersecurity Threat Hunting Guide for SOC Analysts and MSSPs Cyber Security News
Biggest Ever GreedyBear Attack With 650 Hacking Tools Stolen  Million from Victims Biggest Ever GreedyBear Attack With 650 Hacking Tools Stolen $1 Million from Victims Cyber Security News
Hugging Face Considers  Billion Sale Amid AI Security Event Hugging Face Considers $13 Billion Sale Amid AI Security Event Cyber Security News
IRGC Hacker Groups Attacking Targeted Financial, Government, and Media Organizations IRGC Hacker Groups Attacking Targeted Financial, Government, and Media Organizations Cyber Security News
DarkCloud Stealer Attacking Financial Companies With Weaponized RAR Attachments DarkCloud Stealer Attacking Financial Companies With Weaponized RAR Attachments Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Vulnerabilities in Dell ObjectScale Systems Discovered
  • AI Industry Urged to Prioritize Safety to Prevent Potential Risks
  • Passkey Phishing Exploits Target Microsoft Cloud Accounts
  • Plesk Backup Manager Vulnerability Exposes Servers to Risk
  • Revolut Data Breach: Sensitive Customer Info Exposed

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Vulnerabilities in Dell ObjectScale Systems Discovered
  • AI Industry Urged to Prioritize Safety to Prevent Potential Risks
  • Passkey Phishing Exploits Target Microsoft Cloud Accounts
  • Plesk Backup Manager Vulnerability Exposes Servers to Risk
  • Revolut Data Breach: Sensitive Customer Info Exposed

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark