
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-22769 is a hardcoded credential vulnerability (CWE-798) in Dell RecoverPoint for Virtual Machines (RP4VMs) that allows unauthenticated remote attackers to gain unauthorized access to the underlying operating system with root-level persistence. All versions prior to 6.0.3.1 HF1 are affected, including 6.0, 6.0-sp1 through 6.0-sp3_p1 and all earlier releases. The vulnerability was publicly disclosed on February 17–18, 2026, though it had been actively exploited in the wild since at least mid-2024. It carries a CVSS v3.1 base score of 10.0 (Critical) (Dell Advisory, CISA KEV).
The root cause is the use of hard-coded credentials (CWE-798) embedded within the Dell RecoverPoint for Virtual Machines appliance software. An unauthenticated remote attacker who knows or discovers the hardcoded credential can authenticate directly to the underlying operating system over the network — requiring no user interaction and no privileges — and achieve root-level access. The attack vector is network-accessible, with low complexity and a changed scope, meaning the impact extends beyond the vulnerable component itself to the broader virtualization infrastructure. MITRE ATT&CK techniques T1078.001 (Default Accounts) and T1552.001 (Credentials in Files) are directly applicable (Dell Advisory, Google Cloud Blog, SecPod Blog).
Successful exploitation grants an unauthenticated remote attacker full root-level access to the underlying operating system of the RecoverPoint for Virtual Machines appliance, resulting in complete compromise of confidentiality, integrity, and availability. Because RP4VMs is a backup and disaster recovery platform deeply integrated with VMware vSphere environments, a compromised appliance can serve as a beachhead for lateral movement into the broader virtualization infrastructure, enabling data exfiltration, ransomware deployment, or persistent backdoor installation. Threat actors have leveraged this access to deploy the BRICKSTORM, GRIMBOLT, and SLAYSTYLE malware families, establishing long-term covert persistence (Google Cloud Blog, eSentire Advisory, SecPod Blog).
CVE-2026-22769 has been actively exploited in the wild since at least mid-2024 — approximately 18 months before public disclosure — and was added to the CISA Known Exploited Vulnerabilities (KEV) catalog on February 18, 2026, with a federal agency remediation due date of February 21, 2026 (CISA KEV). The primary attributed threat actor is UNC6201, a China-nexus cyberespionage group, which deployed BRICKSTORM, GRIMBOLT, and SLAYSTYLE malware; HAFNIUM and UTA0178 have also been associated with exploitation activity (Google Cloud Blog, BleepingComputer). The EPSS score is approximately 0.3416 (34.16%), reflecting a high probability of exploitation. Attackers used "Ghost NICs" (hidden virtual network interfaces) to evade detection during the campaign (The Register). No public proof-of-concept exploit code has been confirmed, but the vulnerability's trivial exploitation mechanics (known hardcoded credential) make weaponization straightforward (CISA KEV).
/var/log/auth.log or /var/log/secure); root login events from unexpected source IPs; gaps or tampering in system logs consistent with log clearing.nc, socat, custom backdoor binaries); unexpected network listeners on non-standard ports.Dell has released version 6.0.3.1 HF1 as the primary fix and strongly recommends all customers upgrade immediately. For organizations unable to upgrade immediately, Dell also published a remediation script (referenced in DSA-2026-079) that can be applied as a temporary workaround. CISA mandated that all U.S. federal agencies apply mitigations by February 21, 2026 (a 3-day deadline), reflecting the critical severity and active exploitation. Organizations should also restrict network access to RP4VMs management interfaces, monitor for indicators of compromise, and review VMware environments for signs of lateral movement (Dell Advisory, CISA KEV, BleepingComputer).
Dell issued Security Advisory DSA-2026-079 on February 17–18, 2026, describing the vulnerability as critical and urging immediate patching (Dell Advisory). Google Cloud's Mandiant team published a detailed threat intelligence report attributing exploitation to UNC6201 and documenting the BRICKSTORM-to-GRIMBOLT attack chain, which generated significant attention across the security community (Google Cloud Blog). Coverage from BleepingComputer, The Register, SecurityWeek, SC World, and The Hacker News highlighted the 18-month exploitation window and the use of Ghost NICs as a novel evasion technique, drawing widespread commentary on social media platforms including Mastodon, Bluesky, and Reddit (BleepingComputer, The Register). CISA's unusually short 3-day remediation deadline for federal agencies was widely noted as a signal of the vulnerability's severity and active threat (The Record).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."