CVE-2026-81467
9.8
CRITICAL · CVSS 3.1 · EPSS 3% (pctl 87)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Command execution.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 2.99% — more likely to be exploited than 87% of all CVEs |
| Weakness | CWE-78 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2026-09-10 |
| Last modified | 2026-09-16 |
Affected (40)
| Vendor | Product |
|---|---|
| dell | latitude 3330 |
| dell | latitude 3420 |
| dell | latitude 3440 |
| dell | latitude 3450 |
| dell | latitude 5440 |
| dell | latitude 5450 |
| dell | latitude 5520 |
| dell | latitude 5530 |
| dell | latitude 5540 |
| dell | latitude 5550 |
| dell | optiplex 3000 tc |
| dell | optiplex 5400 all-in-one |
| dell | optiplex 7020 |
| dell | optiplex all-in-one 7410 |
| dell | optiplex all-in-one 7420 |
| dell | optiplex micro plus 7010 |
| dell | precision 3260 compact |
| dell | precision 3280 |
| dell | pro 14 pc14250 |
| dell | pro 16 pc16250 |
| dell | pro 16 plus pb16250 |
| dell | pro 24 all-in-one |
| dell | pro 24 all-in-one \(65w\) qc24250 |
| dell | pro 24 all-in-one plus qb24250 |
| dell | pro max 14 |
| dell | pro max 16 plus |
| dell | pro max microfcm2250 |
| dell | pro micro qcm1250 |
| dell | pro micro-thin client q9m1260 |
| dell | pro rugged 13 ra13250 |
| dell | pro rugged 14 rb14250 |
| dell | pro slim low sff |
| dell | pro slim plus xe5 oem qbs1250 |
| dell | pro tower plus xe5 oem qbt1250 |
| dell | pro tower qct1250 |
| dell | thinos |
| dell | wyse 5070 extended thin client |
| dell | wyse 5070 thin client |
| dell | wyse 5470 all-in-one thin client |
| dell | wyse 5470 mtc |
→ the Explorer · watch your stack · NVD