logo

CVE-2026-22769: Critical Dell RecoverPoint Zero-Day Exploited in the Wild

ID: e59305c8-8fa7-5d79-8f69-310ac5f079c3

STIX ID: report--e59305c8-8fa7-5d79-8f69-310ac5f079c3

Feed Name: SOC Prime Blog

Threat Score
90/100

Date Published: 2026-02-18

Date Updated: 2026-04-30

Author: Daryna Olyniychuk

...
...

Researchers (Mandiant and Google TIG) and vendor advisories confirm active exploitation of CVE-2026-22769 — a CVSS 10.0 hardcoded-credential flaw in Dell RecoverPoint for Virtual Machines — by a China-linked cluster (UNC6201) since mid-2024; attackers used Tomcat Manager access to deploy a WAR containing the SLAYSTYLE web shell, achieved root persistence, deployed backdoors (BRICKSTORM, later GRIMBOLT), and moved laterally inside VMware environments using hidden virtual NICs, while Dell recommends upgrading to 6.0.3.1 HF1 or applying a vendor remediation script.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.