The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered government agencies to patch their systems within three days against a maximum-severity Dell vulnerability that has been under active exploitation since mid-2024. According to security researchers from Mandiant and the Google Threat Intelligence Group (GTIG), this hardcoded-credential vulnerability (CVE-2026-22769) in Dell's RecoverPoint (a solution used for VMware virtual machine backup and recovery) is being exploited by a suspected Chinese hacking group tracked as UNC6201. After gaining access to a victim's network in CVE-2026-22769 attacks, UNC6201 deploys several malware payloads, including a newly identified backdoor called Grimbolt. This malware is built using a relatively new compilation technique that makes it harder to analyze than its predecessor, the Brickstorm backdoor. While the group swapped Brickstorm for Grimbolt in September 2025, it's not yet clear whether this switch was part of a planned upgrade or "a reaction to incident response efforts led by Mandiant and other industry partners." "Analysis of incident response engagements revealed that UNC6201, a suspected PRC-nexus threat cluster, has exploited this flaw since at least mid-2024 to move laterally, maintain persistent access, and deploy malware including SLAYSTYLE, BRICKSTORM, and a novel backdoor tracked as GRIMBOLT," they said. The security researchers have also found overlaps between UNC6201 and the Silk Typhoon Chinese state-...
CISA orders feds to patch actively exploited Dell flaw within 3 days
BleepingComputer
·Sergiu Gatlan
·Published Feb 19, 2026
·Updated
Affected Software
1 affected component
Dell RecoverPoint=N/A
Frequently Asked Questions
1
What is the main topic of this article?
The main topic of this article is CISA's order for federal agencies to patch a critical Dell vulnerability that is actively being exploited.
2
What security implications are discussed in the article?
The article discusses the risks posed by a maximum-severity vulnerability in Dell software that could lead to unauthorized access or compromise of federal systems.
3
What products or software are affected by the vulnerability?
The affected product mentioned in the article is Dell RecoverPoint.
4
What is the deadline for federal agencies to apply the patch?
Federal agencies are required to apply the patch within three days of the CISA order.
5
Why is the vulnerability considered high severity?
The vulnerability is considered high severity because it has been under active exploitation and poses significant risks to system security.