FlareStart
HomeNewsHow ToSources
FlareStart

Where developers start their day. All the tech news & tutorials that matter, in one place.

Quick Links

  • Home
  • News
  • Tutorials
  • Sources
  • Privacy Policy

Connect

© 2026 FlareStart. All rights reserved.

Back to articles
CVE-2026-22769: Dell RecoverPoint Zero-Day Exploited by China Since 2024 — CVSS 10.0
NewsSecurity

CVE-2026-22769: Dell RecoverPoint Zero-Day Exploited by China Since 2024 — CVSS 10.0

via Dev.toDeepSeaX1mo ago

A Hardcoded Password. Root Access. Two Years Undetected. Dell shipped a backup product with an admin password hardcoded in a config file. Chinese state hackers found it in mid-2024 and have been quietly exploiting it ever since. CVE-2026-22769 affects Dell RecoverPoint for Virtual Machines — the software organizations trust to protect their VMware infrastructure. CVSS score: 10.0 . Maximum severity. CISA added it to the Known Exploited Vulnerabilities catalog with a 3-day patch deadline for federal agencies. The threat actor, tracked as UNC6201 by Google's Threat Intelligence Group (GTIG), deployed three custom malware families and invented a novel lateral movement technique using ephemeral virtual network interfaces. The Vulnerability: Password in a Config File Dell RecoverPoint for VMs ships with Apache Tomcat as its web management interface. The admin credentials were hardcoded in: /home/kos/tomcat9/tomcat-users.xml Username: admin . Password: hardcoded. This grants full access to t

Continue reading on Dev.to

Opens in a new tab

Read Full Article
25 views

Related Articles

Is 1234567 Divisible by 7?
News

Is 1234567 Divisible by 7?

Medium Programming • 2d ago

News

Fresh Graduate, Zero Experience, One App on the Play Store

Medium Programming • 2d ago

Google Chrome Full Power Unlock | ২১ Super Useful Hidden Features | “Why didn’t I know these…
News

Google Chrome Full Power Unlock | ২১ Super Useful Hidden Features | “Why didn’t I know these…

Medium Programming • 2d ago

Double base64 obfuscation — a data contortion
News

Double base64 obfuscation — a data contortion

Medium Programming • 2d ago

The Kindest Thing for the Next Generation
News

The Kindest Thing for the Next Generation

Medium Programming • 2d ago

Discover More Articles