DSA-2026-214 Security Update for Dell ThinOS 10 for Multiple Vulnerabilities
Summary: Dell ThinOS 10 remediation is available for multiple vulnerabilities that could be exploited by malicious users to compromise the affected system.
Impact
High
Details
|
Third-party Component |
CVEs |
More Information |
|
libpng |
CVE-2026-25646, CVE-2025-28162, CVE-2025-28164 |
|
|
GNU C Library |
CVE-2026-0915, CVE-2025-8058, CVE-2025-15281, CVE-2026-0861 |
|
|
GLib |
CVE-2026-1485, CVE-2026-1484, CVE-2026-1489 |
|
|
Python |
CVE-2025-15282, CVE-2026-0672, CVE-2026-0865, CVE-2025-15366, CVE-2025-15367, CVE-2025-13837, CVE-2025-11468, CVE-2025-12084 |
|
|
libsoup |
CVE-2026-1539, CVE-2026-1536, CVE-2026-1467 |
|
|
Expat |
CVE-2026-24515, CVE-2026-25210 |
|
|
GnuTLS |
CVE-2025-14831, CVE-2025-9820 |
|
|
alsa-lib |
CVE-2026-25068 |
|
|
OpenSSH |
CVE-2025-32728 |
|
Proprietary Code CVEs |
Description |
CVSS Base Score |
CVSS Vector String |
|
CVE-2026-40715 |
Dell ThinOS 10, versions prior to ThinOS10 2602_10.0765, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Privilege Escalation. |
7.8 |
|
|
CVE-2026-40713 |
Dell ThinOS 10, versions prior to ThinOS10 2602_10.0765, contain an Improper Access control vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Information exposure. |
6.1 |
|
Proprietary Code CVEs |
Description |
CVSS Base Score |
CVSS Vector String |
|
CVE-2026-40715 |
Dell ThinOS 10, versions prior to ThinOS10 2602_10.0765, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Privilege Escalation. |
7.8 |
|
|
CVE-2026-40713 |
Dell ThinOS 10, versions prior to ThinOS10 2602_10.0765, contain an Improper Access control vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Information exposure. |
6.1 |
Affected Products & Remediation
|
Product |
Software/Firmware |
Affected Versions |
Remediated Versions |
Release Date (MM/DD/YYYY) |
Link |
|
Latitude 3440 |
ThinOS 10 |
Versions prior to 2602_10.0765_T10 |
Version 2602_10.0765_T10 or later |
05/15/2026 |
|
|
Latitude 5440 |
ThinOS 10 |
Versions prior to 2602_10.0765_T10 |
Version 2602_10.0765_T10 or later |
05/15/2026 |
|
|
Latitude 5450 |
ThinOS 10 |
Versions prior to 2602_10.0765_T10 |
Version 2602_10.0765_T10 or later |
05/15/2026 |
|
|
Latitude 3420 |
ThinOS 10 |
Versions prior to 2602_10.0765_T10 |
Version 2602_10.0765_T10 or later |
05/15/2026 |
|
|
Latitude 5540 |
ThinOS 10 |
Versions prior to 2602_10.0765_T10 |
Version 2602_10.0765_T10 or later |
05/15/2026 |
|
|
Latitude 5550 |
ThinOS 10 |
Versions prior to 2602_10.0765_T10 |
Version 2602_10.0765_T10 or later |
05/15/2026 |
|
|
Latitude 3330 |
ThinOS 10 |
Versions prior to 2602_10.0765_T10 |
Version 2602_10.0765_T10 or later |
05/15/2026 |
|
|
Latitude 3450 |
ThinOS 10 |
Versions prior to 2602_10.0765_T10 |
Version 2602_10.0765_T10 or later |
05/15/2026 |
|
|
Latitude 5520 (MHC) |
ThinOS 10 |
Versions prior to 2602_10.0765_T10 |
Version 2602_10.0765_T10 or later |
05/15/2026 |
|
|
Latitude 5530 (MHC) |
ThinOS 10 |
Versions prior to 2602_10.0765_T10 |
Version 2602_10.0765_T10 or later |
05/15/2026 |
|
|
OptiPlex 7020 |
ThinOS 10 |
Versions prior to 2602_10.0765_T10 |
Version 2602_10.0765_T10 or later |
05/15/2026 |
|
|
OptiPlex All-in-One 7410 |
ThinOS 10 |
Versions prior to 2602_10.0765_T10 |
Version 2602_10.0765_T10 or later |
05/15/2026 |
|
|
OptiPlex All-in-One 7420 |
ThinOS 10 |
Versions prior to 2602_10.0765_T10 |
Version 2602_10.0765_T10 or later |
05/15/2026 |
|
|
OptiPlex Micro Plus 7010 |
ThinOS 10 |
Versions prior to 2602_10.0765_T10 |
Version 2602_10.0765_T10 or later |
05/15/2026 |
|
|
OptiPlex 5400 All-in-One |
ThinOS 10 |
Versions prior to 2602_10.0765_T10 |
Version 2602_10.0765_T10 or later |
05/15/2026 |
|
|
OptiPlex 3000 TC |
ThinOS 10 |
Versions prior to 2602_10.0765_T10 |
Version 2602_10.0765_T10 or later |
05/15/2026 |
|
|
Wyse 5070 Thin Client |
ThinOS 10 |
Versions prior to 2602_10.0765_T10 |
Version 2602_10.0765_T10 or later |
05/15/2026 |
|
|
Wyse 5070 Extended Thin Client |
ThinOS 10 |
Versions prior to 2602_10.0765_T10 |
Version 2602_10.0765_T10 or later |
05/15/2026 |
|
|
Wyse 5470 MTC |
ThinOS 10 |
Versions prior to 2602_10.0765_T10 |
Version 2602_10.0765_T10 or later |
05/15/2026 |
|
|
Wyse 5470 All-in-One Thin Client |
ThinOS 10 |
Versions prior to 2602_10.0765_T10 |
Version 2602_10.0765_T10 or later |
05/15/2026 |
|
|
Dell Pro Rugged 13 RA13250 |
ThinOS 10 |
Versions prior to 2602_10.0765_T10 |
Version 2602_10.0765_T10 or later |
05/15/2026 |
|
|
Dell Pro Rugged 14 RB14250 |
ThinOS 10 |
Versions prior to 2602_10.0765_T10 |
Version 2602_10.0765_T10 or later |
05/15/2026 |
|
|
Dell Pro 16 Plus PB16250 |
ThinOS 10 |
Versions prior to 2602_10.0765_T10 |
Version 2602_10.0765_T10 or later |
05/15/2026 |
|
|
Dell Pro 14 PC14250 |
ThinOS 10 |
Versions prior to 2602_10.0765_T10 |
Version 2602_10.0765_T10 or later |
05/15/2026 |
|
|
Dell Pro 24 All-in-One |
ThinOS 10 |
Versions prior to 2602_10.0765_T10 |
Version 2602_10.0765_T10 or later |
05/15/2026 |
|
|
Dell Pro 16 PC16250 |
ThinOS 10 |
Versions prior to 2602_10.0765_T10 |
Version 2602_10.0765_T10 or later |
05/15/2026 |
|
|
Dell Pro Max 16 Plus |
ThinOS 10 |
Versions prior to 2602_10.0765_T10 |
Version 2602_10.0765_T10 or later |
05/15/2026 |
|
|
Dell Pro Max 14 |
ThinOS 10 |
Versions prior to 2602_10.0765_T10 |
Version 2602_10.0765_T10 or later |
05/15/2026 |
|
|
Dell Pro Tower QCT1250 |
ThinOS 10 |
Versions prior to 2602_10.0765_T10 |
Version 2602_10.0765_T10 or later |
05/15/2026 |
|
|
Dell Pro Slim Low SFF |
ThinOS 10 |
Versions prior to 2602_10.0765_T10 |
Version 2602_10.0765_T10 or later |
05/15/2026 |
|
|
Dell Precision 3260 Compact |
ThinOS 10 |
Versions prior to 2602_10.0765_T10 |
Version 2602_10.0765_T10 or later |
05/15/2026 |
|
|
Dell Precision 3280 |
ThinOS 10 |
Versions prior to 2602_10.0765_T10 |
Version 2602_10.0765_T10 or later |
05/15/2026 |
|
|
Dell Pro 24 All-in-One (65 W) QC24250 |
ThinOS 10 |
Versions prior to 2602_10.0765_T10 |
Version 2602_10.0765_T10 or later |
05/15/2026 |
|
|
Dell Pro 24 All-in-One Plus QB24250 |
ThinOS 10 |
Versions prior to 2602_10.0765_T10 |
Version 2602_10.0765_T10 or later |
05/15/2026 |
|
|
Dell Pro Micro QCM1250 |
ThinOS 10 |
Versions prior to 2602_10.0765_T10 |
Version 2602_10.0765_T10 or later |
05/15/2026 |
|
|
Dell Pro Slim Plus XE5 OEM QBS1250 |
ThinOS 10 |
Versions prior to 2602_10.0765_T10 |
Version 2602_10.0765_T10 or later |
05/15/2026 |
|
|
Dell Pro Tower Plus XE5 OEM QBT1250 |
ThinOS 10 |
Versions prior to 2602_10.0765_T10 |
Version 2602_10.0765_T10 or later |
05/15/2026 |
|
Product |
Software/Firmware |
Affected Versions |
Remediated Versions |
Release Date (MM/DD/YYYY) |
Link |
|
Latitude 3440 |
ThinOS 10 |
Versions prior to 2602_10.0765_T10 |
Version 2602_10.0765_T10 or later |
05/15/2026 |
|
|
Latitude 5440 |
ThinOS 10 |
Versions prior to 2602_10.0765_T10 |
Version 2602_10.0765_T10 or later |
05/15/2026 |
|
|
Latitude 5450 |
ThinOS 10 |
Versions prior to 2602_10.0765_T10 |
Version 2602_10.0765_T10 or later |
05/15/2026 |
|
|
Latitude 3420 |
ThinOS 10 |
Versions prior to 2602_10.0765_T10 |
Version 2602_10.0765_T10 or later |
05/15/2026 |
|
|
Latitude 5540 |
ThinOS 10 |
Versions prior to 2602_10.0765_T10 |
Version 2602_10.0765_T10 or later |
05/15/2026 |
|
|
Latitude 5550 |
ThinOS 10 |
Versions prior to 2602_10.0765_T10 |
Version 2602_10.0765_T10 or later |
05/15/2026 |
|
|
Latitude 3330 |
ThinOS 10 |
Versions prior to 2602_10.0765_T10 |
Version 2602_10.0765_T10 or later |
05/15/2026 |
|
|
Latitude 3450 |
ThinOS 10 |
Versions prior to 2602_10.0765_T10 |
Version 2602_10.0765_T10 or later |
05/15/2026 |
|
|
Latitude 5520 (MHC) |
ThinOS 10 |
Versions prior to 2602_10.0765_T10 |
Version 2602_10.0765_T10 or later |
05/15/2026 |
|
|
Latitude 5530 (MHC) |
ThinOS 10 |
Versions prior to 2602_10.0765_T10 |
Version 2602_10.0765_T10 or later |
05/15/2026 |
|
|
OptiPlex 7020 |
ThinOS 10 |
Versions prior to 2602_10.0765_T10 |
Version 2602_10.0765_T10 or later |
05/15/2026 |
|
|
OptiPlex All-in-One 7410 |
ThinOS 10 |
Versions prior to 2602_10.0765_T10 |
Version 2602_10.0765_T10 or later |
05/15/2026 |
|
|
OptiPlex All-in-One 7420 |
ThinOS 10 |
Versions prior to 2602_10.0765_T10 |
Version 2602_10.0765_T10 or later |
05/15/2026 |
|
|
OptiPlex Micro Plus 7010 |
ThinOS 10 |
Versions prior to 2602_10.0765_T10 |
Version 2602_10.0765_T10 or later |
05/15/2026 |
|
|
OptiPlex 5400 All-in-One |
ThinOS 10 |
Versions prior to 2602_10.0765_T10 |
Version 2602_10.0765_T10 or later |
05/15/2026 |
|
|
OptiPlex 3000 TC |
ThinOS 10 |
Versions prior to 2602_10.0765_T10 |
Version 2602_10.0765_T10 or later |
05/15/2026 |
|
|
Wyse 5070 Thin Client |
ThinOS 10 |
Versions prior to 2602_10.0765_T10 |
Version 2602_10.0765_T10 or later |
05/15/2026 |
|
|
Wyse 5070 Extended Thin Client |
ThinOS 10 |
Versions prior to 2602_10.0765_T10 |
Version 2602_10.0765_T10 or later |
05/15/2026 |
|
|
Wyse 5470 MTC |
ThinOS 10 |
Versions prior to 2602_10.0765_T10 |
Version 2602_10.0765_T10 or later |
05/15/2026 |
|
|
Wyse 5470 All-in-One Thin Client |
ThinOS 10 |
Versions prior to 2602_10.0765_T10 |
Version 2602_10.0765_T10 or later |
05/15/2026 |
|
|
Dell Pro Rugged 13 RA13250 |
ThinOS 10 |
Versions prior to 2602_10.0765_T10 |
Version 2602_10.0765_T10 or later |
05/15/2026 |
|
|
Dell Pro Rugged 14 RB14250 |
ThinOS 10 |
Versions prior to 2602_10.0765_T10 |
Version 2602_10.0765_T10 or later |
05/15/2026 |
|
|
Dell Pro 16 Plus PB16250 |
ThinOS 10 |
Versions prior to 2602_10.0765_T10 |
Version 2602_10.0765_T10 or later |
05/15/2026 |
|
|
Dell Pro 14 PC14250 |
ThinOS 10 |
Versions prior to 2602_10.0765_T10 |
Version 2602_10.0765_T10 or later |
05/15/2026 |
|
|
Dell Pro 24 All-in-One |
ThinOS 10 |
Versions prior to 2602_10.0765_T10 |
Version 2602_10.0765_T10 or later |
05/15/2026 |
|
|
Dell Pro 16 PC16250 |
ThinOS 10 |
Versions prior to 2602_10.0765_T10 |
Version 2602_10.0765_T10 or later |
05/15/2026 |
|
|
Dell Pro Max 16 Plus |
ThinOS 10 |
Versions prior to 2602_10.0765_T10 |
Version 2602_10.0765_T10 or later |
05/15/2026 |
|
|
Dell Pro Max 14 |
ThinOS 10 |
Versions prior to 2602_10.0765_T10 |
Version 2602_10.0765_T10 or later |
05/15/2026 |
|
|
Dell Pro Tower QCT1250 |
ThinOS 10 |
Versions prior to 2602_10.0765_T10 |
Version 2602_10.0765_T10 or later |
05/15/2026 |
|
|
Dell Pro Slim Low SFF |
ThinOS 10 |
Versions prior to 2602_10.0765_T10 |
Version 2602_10.0765_T10 or later |
05/15/2026 |
|
|
Dell Precision 3260 Compact |
ThinOS 10 |
Versions prior to 2602_10.0765_T10 |
Version 2602_10.0765_T10 or later |
05/15/2026 |
|
|
Dell Precision 3280 |
ThinOS 10 |
Versions prior to 2602_10.0765_T10 |
Version 2602_10.0765_T10 or later |
05/15/2026 |
|
|
Dell Pro 24 All-in-One (65 W) QC24250 |
ThinOS 10 |
Versions prior to 2602_10.0765_T10 |
Version 2602_10.0765_T10 or later |
05/15/2026 |
|
|
Dell Pro 24 All-in-One Plus QB24250 |
ThinOS 10 |
Versions prior to 2602_10.0765_T10 |
Version 2602_10.0765_T10 or later |
05/15/2026 |
|
|
Dell Pro Micro QCM1250 |
ThinOS 10 |
Versions prior to 2602_10.0765_T10 |
Version 2602_10.0765_T10 or later |
05/15/2026 |
|
|
Dell Pro Slim Plus XE5 OEM QBS1250 |
ThinOS 10 |
Versions prior to 2602_10.0765_T10 |
Version 2602_10.0765_T10 or later |
05/15/2026 |
|
|
Dell Pro Tower Plus XE5 OEM QBT1250 |
ThinOS 10 |
Versions prior to 2602_10.0765_T10 |
Version 2602_10.0765_T10 or later |
05/15/2026 |
For details on ThinOS lifecycle information refer to - Dell Thin Client Solutions and thin client OS Lifecycle Information
Revision History
| Revision | Date | Description |
|---|---|---|
| 1.0 | 2026-05-20 | Initial Release |
Acknowledgements
CVE-2026-40715: Dell would like to thank Brandon Schreiber for reporting this issue.
CVE-2026-40713: Dell would like to thank Darren McDonald from AmberWolf and Christophe Schleypen (NATO Cyber Security Centre – NCSC) for reporting this issue.