Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2336 articles · 160855 vulns · 36/41 feeds (7d)
← Back to list
6.1
CVE-2026-40713EXPLOITEDPATCHED
dell · thinos

CVE-2026-40713: Dell ThinOS 10, versions prior to ThinOS10 2602_10.0765, contain an Improper Access control vulnerability. An unauthenti

Description

Dell ThinOS 10, versions prior to ThinOS10 2602_10.0765, contain an Improper Access control vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Information exposure.

Affected Products

VendorProductVersions
dellthinos0

References

  • https://www.dell.com/support/kbdoc/en-us/000463678/dsa-2026-214(vendor-advisory)

Related News (1 articles)

Tier C
VulDB5d ago
CVE-2026-40713 | Dell ThinOS 10 10.0765 access control (dsa-2026-214)
→ No new info (linked only)
CVSS 3.16.1 MEDIUM
VectorCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
2602_10.0765_T10
CWECWE-284
PublishedJun 2, 2026
Last enriched5d agov2
Trending Score19
Source articles1
Independent1
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2025-46638
CVE-2025-46638: Dell BSAFE SSL-J contains an allocation of resources without limits or throttling vulnerability. An unauthenticated remo
Trending: 24
PRE-CVE
Multiple Vulnerabilities in Dell Products Including Dell Private Cloud, PowerSwitch Z9864F-ON, Dell Automation Platform, and Dell VxRail Appliance
Trending: 20
HIGHCVE-2026-40715
CVE-2026-40715: Dell ThinOS 10, versions prior to ThinOS10 2602_10.0765, contain an Improper Access Control vulnerability. A low privile
Trending: 16
MEDIUMCVE-2026-35070
CVE-2026-35070: Dell SmartFabric Storage Software, versions prior to 1.4.5, contains an Improper Neutralization of Special Elements used
Trending: 8
NONECVE-2026-9489EXP
NitroSense V3: Local Privilege Escalation (LPE) vulnerability
Trending: 5

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 2, 2026
Discovered by ZDM
Jun 2, 2026
Updated: severity, activelyExploited
Jun 2, 2026
Actively Exploited
Jun 2, 2026
Patch Available
Jun 2, 2026

Version History

v2
Last enriched 5d ago
v2Tier C5d ago

Updated severity to CRITICAL, marked as actively exploited, and noted that no exploit is available.

severityactivelyExploited
via VulDB
v15d ago

Initial creation