CVE-2026-81048

Dell ThinOS 10, versions prior to 2605_10.2616, contain an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Remote Code execution

  • Published Sep 10, 2026
  • CVSS 8.8 high
  • 2.4% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-81048 at the National Vulnerability Database