peter bassill · operator
$ cve CVE-2026-81467 JSON

CVE-2026-81467

9.8
CRITICAL · CVSS 3.1 · EPSS 3% (pctl 87)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Command execution.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS2.99% — more likely to be exploited than 87% of all CVEs
WeaknessCWE-78
On CISA KEVno
Public exploitnone known
Published2026-09-10
Last modified2026-09-16

Affected (40)

VendorProduct
delllatitude 3330
delllatitude 3420
delllatitude 3440
delllatitude 3450
delllatitude 5440
delllatitude 5450
delllatitude 5520
delllatitude 5530
delllatitude 5540
delllatitude 5550
delloptiplex 3000 tc
delloptiplex 5400 all-in-one
delloptiplex 7020
delloptiplex all-in-one 7410
delloptiplex all-in-one 7420
delloptiplex micro plus 7010
dellprecision 3260 compact
dellprecision 3280
dellpro 14 pc14250
dellpro 16 pc16250
dellpro 16 plus pb16250
dellpro 24 all-in-one
dellpro 24 all-in-one \(65w\) qc24250
dellpro 24 all-in-one plus qb24250
dellpro max 14
dellpro max 16 plus
dellpro max microfcm2250
dellpro micro qcm1250
dellpro micro-thin client q9m1260
dellpro rugged 13 ra13250
dellpro rugged 14 rb14250
dellpro slim low sff
dellpro slim plus xe5 oem qbs1250
dellpro tower plus xe5 oem qbt1250
dellpro tower qct1250
dellthinos
dellwyse 5070 extended thin client
dellwyse 5070 thin client
dellwyse 5470 all-in-one thin client
dellwyse 5470 mtc

References

→ the Explorer  ·  watch your stack  ·  NVD