CVE-2026-22769: Critical Dell RecoverPoint Zero-Day Exploited in the Wild
ID: e59305c8-8fa7-5d79-8f69-310ac5f079c3
STIX ID: report--e59305c8-8fa7-5d79-8f69-310ac5f079c3
Feed Name: SOC Prime Blog
Researchers (Mandiant and Google TIG) and vendor advisories confirm active exploitation of CVE-2026-22769 — a CVSS 10.0 hardcoded-credential flaw in Dell RecoverPoint for Virtual Machines — by a China-linked cluster (UNC6201) since mid-2024; attackers used Tomcat Manager access to deploy a WAR containing the SLAYSTYLE web shell, achieved root persistence, deployed backdoors (BRICKSTORM, later GRIMBOLT), and moved laterally inside VMware environments using hidden virtual NICs, while Dell recommends upgrading to 6.0.3.1 HF1 or applying a vendor remediation script.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
