logo

CISA gives federal agencies three days to patch actively exploited Dell bug

ID: 6a1123d4-e578-5474-8e58-2f4142d532ae

STIX ID: report--6a1123d4-e578-5474-8e58-2f4142d532ae

Feed Name: The Register (Security)

Threat Score
88/100

Date Published: 2026-02-20

Date Updated: 2026-04-26

Author: Carly Page

...
...

CISA added CVE-2026-22769 (hardcoded credentials in Dell RecoverPoint for Virtual Machines) to its Known Exploited Vulnerabilities catalog and ordered federal agencies to patch within three days after Dell disclosed active exploitation; Mandiant links the flaw to UNC6201 (with overlaps to China-nexus Silk Typhoon) which has used the issue since mid-2024 to move laterally, maintain persistence, and deploy implants including Brickstorm, Grimbolt, and Slaystyle while leveraging stealth techniques such as Ghost NICs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.