LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-22769: Dell RecoverPoint for Virtual Machines (RP4VMs) Use of Hard-coded Credentials Vulnerability

RBRecent Breaches Vulnerability Intelligence·Feb 18, 2026
CVSS 10.0 · Critical⚠ Actively exploited (CISA KEV)
10.0
CVSS score
Critical
Severity
Active
CISA KEV
No
Ransomware use
Feb 21, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-22769 to its Known Exploited Vulnerabilities catalog on Feb 18, 2026, with a federal patch deadline of Feb 21, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Dell RecoverPoint for Virtual Machines, versions prior to 6.0.3.1 HF1, contain a hardcoded credential vulnerability. This is considered critical as an unauthenticated remote attacker with knowledge of the hardcoded credential could potentially exploit this vulnerability leading to unauthorized access to the underlying operating system and root-level persistence. Dell recommends that customers upgrade or apply one of the remediations as soon as possible.

This vulnerability affects Dell RecoverPoint for Virtual Machines (RP4VMs). It stems from the use of hard-coded credentials and could allow an unauthenticated remote attacker to reach the underlying operating system with root-level persistence.

How it works

The weakness is categorized as CWE-798, use of hard-coded credentials. In products of this class an embedded credential set remains present in the software image or configuration. An attacker who knows or discovers the value can supply it directly over the network without prior authentication. Successful use grants a shell or equivalent access on the host operating system and the ability to establish persistent root-level control.

Am I affected? How to find it in your systems

How to remediate

Apply the vendor-supplied update referenced in the official advisory. After patching, review and, where supported, replace or disable any remaining static credential mechanisms used by management or replication services. Follow the vendor’s hardening checklist for the product class, which commonly includes restricting management interfaces to trusted networks and enforcing certificate-based or multi-factor authentication where the software permits.

If you can't patch immediately

If your data may have been exposed

Compromise of systems that hold replication and recovery data can lead to unauthorized access or destruction of protected workloads. Organizations that discover an active intrusion should assume credentials and persisted access may have been obtained. You can run a free exposure scan of your email addresses against known breach data to check for related account exposure.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedDell · RecoverPoint for Virtual Machines (RP4VMs)
WeaknessCWE-798
CVSS base score10.0 (Critical)
CVSS vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
PublishedFeb 17, 2026
Added to CISA KEVFeb 18, 2026
Federal patch deadlineFeb 21, 2026
Known ransomware useNot documented
Check if your data is exposed →

References

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities