CRITICALCISA KEVIN THE WILD

CVE-2026-22769

CWE-798Published: February 18, 2026· Updated: Jun 17, 2026

10.0
CVSS v3.1
EPSS:28.78%probability of exploitation in 30 daysPercentile:96.4th

Official Description

Dell RecoverPoint for Virtual Machines, versions prior to 6.0.3.1 HF1, contain a hardcoded credential vulnerability. This is considered critical as an unauthenticated remote attacker with knowledge of the hardcoded credential could potentially exploit this vulnerability leading to unauthorized access to the underlying operating system and root-level persistence. Dell recommends that customers upgrade or apply one of the remediations as soon as possible.

NVD Source

Risk Analysis

This critical vulnerability in Dell RecoverPoint for Virtual Machines involves hardcoded credentials, allowing an unauthenticated remote attacker to gain root-level access to the underlying operating system. The CVSS score of 10.0 and high EPSS score of 0.34162 highlight the extreme urgency of addressing this flaw.

This vulnerability is actively exploited in the wild and is included in CISA's KEV catalog, confirming its active use by threat actors. The CVSS vector indicates it is remotely exploitable with low attack complexity and no user interaction required.

Recommended Action

It is critical to upgrade Dell RecoverPoint for Virtual Machines to version 6.0.3.1 HF1 or later immediately. Follow Dell's remediation guidance to mitigate this severe risk.

Generated by the CTIWATCH analysis pipeline from this CVE's metadata (CVSS, EPSS, KEV status, exploit intelligence). Verify against vendor advisories before acting.

Technical Analysis

CVE-2026-22769 can be exploited remotely over the network without requiring physical or adjacent access, significantly expanding the attack surface for threat actors.

The vulnerability requires no privileges and no user interaction, making it a prime target for automated exploitation campaigns and worm-like propagation.

A successful exploit results in complete confidentiality breach (data exposure), full integrity compromise (data manipulation), availability disruption (denial of service), with a CVSS base score of 10.0.

The vulnerability has a "Changed" scope, meaning successful exploitation can impact components beyond the vulnerable component itself — such as the host operating system or adjacent services.

CISA has added CVE-2026-22769 to the Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation in the wild. U.S. federal agencies are required to patch this within the mandated timeframe, and all organizations should treat remediation as urgent.

CVSS v3.1 Vector Breakdown

Exploitability
Attack VectorNetwork
Attack ComplexityLow
Privileges Req.None
User InteractionNone
ScopeChanged
Impact
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Affected Vendors & Products

Dell1 product(s)
recoverpoint for virtual machines
Source: NVD CPE · 2 total CPE entries

Exploit & PoC Resources

ACTIVE EXPLOITATIONConfirmed exploitation in the wild
External links open in a new tab. Always verify in a controlled environment before use.

Official Patches & Advisories

News & Research Mentioning CVE-2026-22769

Fed agencies ordered to patch Dell bug by Saturday after exploitation warning
The Record· Feb 18, 2026

Dell and Google released notices on Tuesday about CVE-2026-22769, warning that a sophisticated Chinese actor has been targeting the bug since at least mid-2024. [xlite_meta score:56 src:The Record xlite_fp:83a71e3c742bf8d1c588e613eea818c0b34d5f3b8832c58bcd14dc8c969ec853]

CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA Alerts· Feb 18, 2026

CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2021-22175 GitLab Server-Side Request Forgery (SSRF) Vulnerability CVE-2026-22769 Dell RecoverPoint for Virtual Machines (RP4VMs) Use of Hard-coded Credentials Vulnerability These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive [xlite_meta score:51 src:CISA Alerts xlite_fp:2312edec4bd01cf3701650d4424a63734849126101967e9e5493d26777a51e21]

Dell RecoverPoint for VMs Zero-Day CVE-2026-22769 Exploited Since Mid-2024
The Hacker News· Feb 18, 2026

A maximum severity security vulnerability in Dell RecoverPoint for Virtual Machines has been exploited as a zero-day by a suspected China-nexus threat cluster dubbed UNC6201 since mid-2024, according to a new report from Google Mandiant and Google Threat Intelligence Group (GTIG). The activity involves the exploitation of CVE-2026-22769 (CVSS score: 10.0), a case of hard-coded credentials [xlite_meta score:49 src:The Hacker News xlite_fp:7edbb7259c4297c1edc51c84b43bef8fa9411c10915e904bcf6e6820ff07319f]

Dell RecoverPoint Zero-Day Exploited by Chinese Cyberespionage Group
SecurityWeek· Feb 18, 2026

GTIG and Mandiant said the zero-day tracked as CVE-2026-22769 has been exploited by UNC6201 since at least 2024. The post Dell RecoverPoint Zero-Day Exploited by Chinese Cyberespionage Group appeared first on SecurityWeek. [xlite_meta score:46 src:SecurityWeek xlite_fp:79bb126a00d2867b70fae9cfd5c439bb2fd0435235583d11ac99675676335f6b]

From BRICKSTORM to GRIMBOLT: UNC6201 Exploiting a Dell RecoverPoint for Virtual Machines Zero-Day
Mandiant Blog· Feb 17, 2026

Written by: Peter Ukhanov, Daniel Sislo, Nick Harbour, John Scarbrough, Fernando Tomlinson, Jr., Rich Reece Introduction Mandiant and Google Threat Intelligence Group (GTIG) have identified the zero-day exploitation of a high-risk vulnerability in Dell RecoverPoint for Virtual Machines, tracked as CVE-2026-22769, with a CVSSv3.1 score of 10.0. Analysis of incident response engagements revealed that UNC6201, a suspected PRC-nexus threat cluster, has exploited this flaw since at least mid-2024 to move laterally, maintain persistent access, and deploy malware including SLAYSTYLE, BRICKSTORM, and a novel backdoor tracked as GRIMBOLT. The initial access vector for these incidents was not confirmed, but UNC6201 is known to target edge appliances (such as VPN concentrators) for initial access. There are notable overlaps between UNC6201 and UNC5221, which has been used synonymously with the actor publicly reported as Silk Typhoon, although GTIG does not currently consider the two clusters to b

All References (3)

Quick Facts

CVE IDCVE-2026-22769
CVSS Score10.0 / 10
SeverityCRITICAL
WeaknessCWE-798
CISA KEVYES — Active Exploitation
ExploitIN THE WILD
EPSS (30d)28.78%
Affected1 vendor(s)
PublishedFeb 18, 2026

Known Threat Actors

wa
financial
storm
financial
lv
financial
vect
financial
pear
financial
core
financial

Organizations Hit via This CVE5

Related CVEs (CWE-798)

Recommended Actions

  • Apply vendor patches immediately
  • Monitor CVE-2026-22769 in threat intel feeds
  • Review IDS/IPS signatures for exploitation attempts
  • !CISA KEV: Federal agencies must patch per BOD 22-01 timeline
  • !Active exploitation confirmed — treat as P1
Data sourced from NVD (NIST), CISA KEV, and EPSS (FIRST). Analysis generated by CTIWatch. CVE data is provided under the NVD usage policy.