DELL Security Advisory
Published Date: Not specified
CVE: CVE-2026-20707
Advisory Summary
🔷 Title: DSA-2026-355 — Security Update for Dell PowerEdge Server (Intel 2026 Security Advisories, 2026.3 IPU)
⚠️ Severity: High
Dell has released DSA-2026-355 addressing multiple high-impact security issues affecting Dell PowerEdge servers with Intel 2026 security advisories integrated via the 2026.3 IPU.
- CVE-2026-20707
- CVE-2025-35973
- CVE-2026-20775
- CVE-2026-20705
- CVE-2026-20712
- CVE-2026-20901
- CVE-2026-6727
- CVE-2026-6726
- CVE-2026-20917
- CVE-2026-20885
- PowerEdge R770 / R670 / R570 / R470
- PowerEdge XE7740 / XE9780 / XE9780L
- PowerEdge R770AP / XE9780LAP
- data center lifecycle hardening
- compliance (firmware integrity expectations)
- incident prevention in hybrid/hardened environments
âś… Actionable steps for IT/Infrastructure teams
1. Triage inventory: Confirm which listed PowerEdge models are in scope in your environment (including BIOS/firmware baselines).
2. Validate current IPU/firmware level: Compare against the advisory’s 2026.3 IPU update requirement.
3. Plan controlled maintenance: Schedule firmware updates with appropriate reboot windows and rollback readiness.
4. Verify post-update posture: Re-check BIOS/firmware versions and run standard platform verification procedures.
5. Harden access & auditing: Ensure iDRAC/iKVM and management plane controls are compliant while updates are deployed.
🔎 Alarms & Warnings
⚠️ Warning: Treat this as a High priority firmware remediation—delayed updates increase exposure to platform-level attack chains.
🚨 Alarm: Prioritize systems with public exposure, high-privilege workloads, or shared tenancy.
📌
Reference: Vendor Advisory