Official source evidencewww.dell.comVersioned article
Official source article · www.dell.com

DSA-2026-060: Security Update for Dell PowerProtect Data Domain Multiple Vulnerabilities | Dell US

BlackTree keeps a versioned source snapshot and links it to relevant CVE reports. The publisher remains authoritative for product applicability, release details and installation guidance.

Read the official article ↗
Publisherwww.dell.com
Article IDNo stable ID in source URL
Verified snapshot29 Sept 2026, 08:14 UTC
Linked CVEs27

Linked CVE reports

These are source relationships, not a claim that this article fixes every affected product or branch.

  • CVE-2026-35073Dell PowerProtect Data Domain — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
  • CVE-2026-35154Dell PowerProtect Data Domain appliances — Improper Privilege Management
  • CVE-2026-35072Dell PowerProtect Data Domain — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
  • CVE-2026-35153Dell PowerProtect Data Domain — Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
  • CVE-2026-35074Dell PowerProtect Data Domain — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
  • CVE-2026-26354Dell PowerProtect Data Domain — Stack-based Buffer Overflow
  • CVE-2026-26951Dell PowerProtect Data Domain — Stack-based Buffer Overflow
  • CVE-2026-22761Dell PowerProtect Data Domain, versions 8.5 through 8.6 contain a command injection vulnerability
  • CVE-2026-26942Dell PowerProtect Data Domain, versions 8.5 through 8.6 contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS command injection vulnerability
  • CVE-2026-26943Dell PowerProtect Data Domain — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
  • CVE-2026-24506Dell PowerProtect Data Domain — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
  • CVE-2026-24505Dell PowerProtect Data Domain, versions 8.5 through 8.6 contain an improper input validation vulnerability
  • CVE-2026-24504Dell PowerProtect Data Domain — Improper Input Validation
  • CVE-2026-23774Dell PowerProtect Data Domain — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
  • CVE-2026-26944Dell PowerProtect Data Domain — Missing Authentication for Critical Function
  • CVE-2026-23776Dell PowerProtect Data Domain — Improper Certificate Validation
  • CVE-2025-46605Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 contain a session fixation vulnerability
  • CVE-2026-23853Dell PowerProtect Data Domain — Use of Weak Credentials
  • CVE-2025-36568Dell PowerProtect Data Domain BoostFS: Insufficiently Protected Credentials
  • CVE-2026-23778Dell PowerProtect Data Domain — Improper Neutralization of Special Elements used in a Command ('Command Injection')
  • CVE-2026-23779Dell PowerProtect Data Domain — Improper Neutralization of Special Elements used in a Command ('Command Injection')
  • CVE-2025-46607Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 contain an improper authentication vulnerability
  • CVE-2025-46641Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 contain an improper authentication vulnerability
  • CVE-2025-46606Dell PowerProtect Data Domain: Improper Restriction of Excessive Authentication Attempts
  • CVE-2026-28263Dell PowerProtect Data Domain — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
  • CVE-2026-23777Dell PowerProtect Data Domain — Exposure of Sensitive Information to an Unauthorized Actor
  • CVE-2026-23775Dell PowerProtect Data Domain appliances — Insertion of Sensitive Information into Log File

Source and provenance

Original title: DSA-2026-060: Security Update for Dell PowerProtect Data Domain Multiple Vulnerabilities | Dell US. Captured 29 Sept 2026, 08:14 UTC. The stored article is used for enrichment and change detection; BlackTree does not republish the publisher's full text here.

Open the publisher's current version ↗