VulnSea

update_package_framework vulnerabilities

CVEs whose affected-version data names the update_package_framework package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

5 CVEsRSS

CVE-2026-71179High· 7.3
5d ago

Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability

Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentiall…

Twilightdell · update_package_frameworkEPSS 0.51%via NVD
CVE-2026-71180High· 8.2
5d ago

Dell Update Package Framework, versions prior to 26.07.03, contains an Unchecked Return Value vulnerability

Dell Update Package Framework, versions prior to 26.07.03, contains an Unchecked Return Value vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.

Twilightdell · update_package_frameworkEPSS 0.13%via NVD
CVE-2026-71182Low· 3.0
5d ago

Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability

Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerabilit…

Sunlitdell · update_package_frameworkEPSS 0.12%via NVD
CVE-2026-71181Low· 3.0
5d ago

Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability

Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerabilit…

Sunlitdell · update_package_frameworkEPSS 0.12%via NVD
CVE-2026-86358Medium· 6.5
5d ago

Dell Update Package Framework, versions prior to 26.07.03, contains a Stack-based Buffer Overflow vulnerability

Dell Update Package Framework, versions prior to 26.07.03, contains a Stack-based Buffer Overflow vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Remote exe…

Sunlitdell · update_package_frameworkEPSS 0.30%via NVD
update_package_framework vulnerabilities (CVEs) · VulnSea