<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/cisa-gives-feds-3-days-to-patch-actively-exploited-dell-bug-doyny65jr" -->

---
title: CISA gives feds 3 days to patch actively exploited Dell bug
description: CISA has added CVE-2026-22769, a maximum-severity hardcoded credential flaw in Dell RecoverPoint for Virtual Machines, to its Known Exploited Vulnerabilities...
canonical: https://daily.dev/posts/cisa-gives-feds-3-days-to-patch-actively-exploited-dell-bug-doyny65jr
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: CISA gives feds 3 days to patch actively exploited Dell bug | daily.dev
og:description: CISA has added CVE-2026-22769, a maximum-severity hardcoded credential flaw in Dell RecoverPoint for Virtual Machines, to its Known Exploited Vulnerabilities...
og:url: https://daily.dev/posts/cisa-gives-feds-3-days-to-patch-actively-exploited-dell-bug-doyny65jr
og:image: https://api.daily.dev/og/posts/dOYNy65jr.png
og:image:alt: CISA gives feds 3 days to patch actively exploited Dell bug
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# CISA gives feds 3 days to patch actively exploited Dell bug

**[The Register](https://daily.dev/sources/theregister)** · 3 min read · 0 upvotes · 0 comments

## Summary

CISA has added CVE-2026-22769, a maximum-severity hardcoded credential flaw in Dell RecoverPoint for Virtual Machines, to its Known Exploited Vulnerabilities catalog, giving federal agencies just three days to patch. The vulnerability has been actively exploited since at least mid-2024 by suspected China-nexus operators (tracked as UNC6201, with links to Silk Typhoon), who used it for lateral movement, persistence, and deploying malware including the Brickstorm backdoor, Grimbolt implant, and Slaystyle. Attackers also deployed 'Ghost NICs' on virtual machines to evade detection. Mandiant has confirmed fewer than a dozen victims so far, though the actual count may be higher.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://go.theregister.com/feed/www.theregister.com/2026/02/20/cisa_dell_vulnerability/>

---

Tags: [#tech-news](https://daily.dev/tags/tech-news), [#security](https://daily.dev/tags/security), [#cyber](https://daily.dev/tags/cyber)

[View this post on daily.dev](https://daily.dev/posts/cisa-gives-feds-3-days-to-patch-actively-exploited-dell-bug-doyny65jr)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"CISA gives feds 3 days to patch actively exploited Dell bug","url":"https://daily.dev/posts/cisa-gives-feds-3-days-to-patch-actively-exploited-dell-bug-doyny65jr","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/cisa-gives-feds-3-days-to-patch-actively-exploited-dell-bug-doyny65jr"},"datePublished":"2026-02-20T12:19:15.499Z","dateModified":"2026-02-26T17:35:17.797Z","description":"CISA has added CVE-2026-22769, a maximum-severity hardcoded credential flaw in Dell RecoverPoint for Virtual Machines, to its Known Exploited Vulnerabilities...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/ea307f2a0c8892ddd90cdf2ff7fb4e5b?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/ea307f2a0c8892ddd90cdf2ff7fb4e5b?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"The Register","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"The Register","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/66aa2113fdad463992ffcbf0e8963fda","url":"https://daily.dev/sources/theregister"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/cisa-gives-feds-3-days-to-patch-actively-exploited-dell-bug-doyny65jr","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"tech-news,security,cyber","timeRequired":"PT3M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"The Register","item":"https://daily.dev/sources/theregister"},{"@type":"ListItem","position":3,"name":"CISA gives feds 3 days to patch actively exploited Dell bug"}]}
```

