BlackTreeCVE IntelligenceOfficial source evidencewww.dell.comVersioned article
Official source article · www.dell.com
DSA-2026-060: Security Update for Dell PowerProtect Data Domain Multiple Vulnerabilities | Dell US
BlackTree keeps a versioned source snapshot and links it to relevant CVE reports. The publisher remains authoritative for product applicability, release details and installation guidance.
Read the official article ↗Publisherwww.dell.com
Article IDNo stable ID in source URL
Verified snapshot29 Sept 2026, 08:14 UTC
Linked CVEs27
Linked CVE reports
These are source relationships, not a claim that this article fixes every affected product or branch.
- CVE-2026-35073Dell PowerProtect Data Domain — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
- CVE-2026-35154Dell PowerProtect Data Domain appliances — Improper Privilege Management
- CVE-2026-35072Dell PowerProtect Data Domain — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
- CVE-2026-35153Dell PowerProtect Data Domain — Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
- CVE-2026-35074Dell PowerProtect Data Domain — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
- CVE-2026-26354Dell PowerProtect Data Domain — Stack-based Buffer Overflow
- CVE-2026-26951Dell PowerProtect Data Domain — Stack-based Buffer Overflow
- CVE-2026-22761Dell PowerProtect Data Domain, versions 8.5 through 8.6 contain a command injection vulnerability
- CVE-2026-26942Dell PowerProtect Data Domain, versions 8.5 through 8.6 contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS command injection vulnerability
- CVE-2026-26943Dell PowerProtect Data Domain — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
- CVE-2026-24506Dell PowerProtect Data Domain — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
- CVE-2026-24505Dell PowerProtect Data Domain, versions 8.5 through 8.6 contain an improper input validation vulnerability
- CVE-2026-24504Dell PowerProtect Data Domain — Improper Input Validation
- CVE-2026-23774Dell PowerProtect Data Domain — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
- CVE-2026-26944Dell PowerProtect Data Domain — Missing Authentication for Critical Function
- CVE-2026-23776Dell PowerProtect Data Domain — Improper Certificate Validation
- CVE-2025-46605Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 contain a session fixation vulnerability
- CVE-2026-23853Dell PowerProtect Data Domain — Use of Weak Credentials
- CVE-2025-36568Dell PowerProtect Data Domain BoostFS: Insufficiently Protected Credentials
- CVE-2026-23778Dell PowerProtect Data Domain — Improper Neutralization of Special Elements used in a Command ('Command Injection')
- CVE-2026-23779Dell PowerProtect Data Domain — Improper Neutralization of Special Elements used in a Command ('Command Injection')
- CVE-2025-46607Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 contain an improper authentication vulnerability
- CVE-2025-46641Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 contain an improper authentication vulnerability
- CVE-2025-46606Dell PowerProtect Data Domain: Improper Restriction of Excessive Authentication Attempts
- CVE-2026-28263Dell PowerProtect Data Domain — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- CVE-2026-23777Dell PowerProtect Data Domain — Exposure of Sensitive Information to an Unauthorized Actor
- CVE-2026-23775Dell PowerProtect Data Domain appliances — Insertion of Sensitive Information into Log File
Source and provenance
Original title: DSA-2026-060: Security Update for Dell PowerProtect Data Domain Multiple Vulnerabilities | Dell US. Captured 29 Sept 2026, 08:14 UTC. The stored article is used for enrichment and change detection; BlackTree does not republish the publisher's full text here.
Open the publisher's current version ↗