Dell RecoverPoint credential flaw abused for persistent access
Case score 65
Case score is a discovery signal based on public evidence, not a guaranteed risk rating. Use it to decide what to review first, then verify important details from the linked sources.
- Total
- 65
- Main story score
- 62
- Related evidence lift
- +3 / 20
- Contributing updates
- 1
- Context updates
- 0
- Vulnerability Critical hardcoded-credential flaw in Dell RecoverPoint for Virtual Machines; active zero-day exploitation began in mid-2024 and enabled OS access and root-level persistence. main
- Campaign Direct follow-on campaign record for the same Dell RecoverPoint exploitation path; adds post-compromise tooling, persistence, and ESXi pivoting detail. contributes
Overview
Latest development Open development history CISA orders FCEB agencies to patch CVE-2026-22769 CISA added CVE-2026-22769 in Dell RecoverPoint for Virtual Machines to its Known Exploited Vulnerabilities catalog and ordered Federal Civilian Executive Branch agencies to secure their networks by the end of Saturday, February 21, under Binding Operational Directive 22-01; CISA warned that the flaw is actively exploited and advised agencies to apply vendor mitigations or stop using the product if mitigations are unavailable.
-
UNC6201 exploits Dell RecoverPoint zero-day
UNC6201 has been exploiting CVE-2026-22769 in Dell RecoverPoint for Virtual Machines in zero-day attacks since mid-2024, creating a path to unauthorized access and root-level persistence on vulnerable systems; after initial access, the group deployed Grimbolt and Brickstorm and used Ghost NICs on VMware ESXi servers to pivot deeper into victim networks.
-
UNC6201 exploitation of Dell RecoverPoint flaw revealed
Mandiant and the Google Threat Intelligence Group say UNC6201 has quietly exploited CVE-2026-22769 in Dell RecoverPoint for Virtual Machines since mid-2024, where a hardcoded credential in versions prior to 6.0.3.1 HF1 could let an unauthenticated remote attacker gain unauthorized access and root-level persistence; after access, the group deployed Grimbolt and Brickstorm, used Ghost NICs on VMware ESXi servers, and showed overlaps with UNC5221, Silk Typhoon, Warp Panda, and related activity targeting multiple U.S. organizations.