boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Tuesday, October 6, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2026-22769

Dell RecoverPoint for Virtual Machines (RP4VMs)
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  H  H   10.0   .1335   96.3   YES
AFFECTED
  Product                            Versions                                                                              Fixed
  RecoverPoint for Virtual Machines  5.3 SP4 P1 –                                                                          —
  RecoverPoint for Virtual Machines  6.0, 6.0 SP1, 6.0 SP1 P1, 6.0 SP1 P2, 6.0 SP2, 6.0 SP2 P1, 6.0 SP3, and 6.0 SP3 P1 –  —
TIMELINE
  Jan 9   Reserved by dell
  Feb 17  Published (CNA: dell)
  Feb 18  Added to CISA KEV, remediation due 2026-02-21
CWE-798 · CNA: dell · CVSS v3.1 · 3 references · KEV due February 21, 2026

Description

Dell RecoverPoint for Virtual Machines, versions prior to 6.0.3.1 HF1, contain a hardcoded credential vulnerability. This is considered critical as an unauthenticated remote attacker with knowledge of the hardcoded credential could potentially exploit this vulnerability leading to unauthorized access to the underlying operating system and root-level persistence. Dell recommends that customers upgrade or apply one of the remediations as soon as possible.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
January 9, 2026ReservedReserved by dell
February 17, 2026PublishedPublished (CNA: dell)
February 18, 2026KEV ADDEDAdded to CISA KEV, remediation due 2026-02-21

Affected

Affected products and packages — 2 rows
VendorProduct / PackageEcosystemVersion introducedFixed
DellRecoverPoint for Virtual Machines—5.3 SP4 P1—
DellRecoverPoint for Virtual Machines—6.0, 6.0 SP1, 6.0 SP1 P1, 6.0 SP1 P2, 6.0 SP2, 6.0 SP2 P1, 6.0 SP3, and 6.0 SP3 P1—

Weaknesses

CWE-798

References (3)

Related

Authoritative record: CVE-2026-22769 at cve.org

Vendors: dell

Weaknesses: CWE-798

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-22769 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Tuesday, October 6, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.