External risk intelligence

Dell SmartFabric OS10 Download of Code Without Integrity Check Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-63696

The vulnerability affects Dell SmartFabric OS10, which is network operating system software for data center switches. These devices are typically deployed within internal data center network fabrics or management segments, making direct public internet exposure uncommon and contrary to standard security practices.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a vulnerability in Dell SmartFabric OS10 Software that, if exploited, could allow a privileged remote attacker to execute code. The primary concern is confirming the relevance and exposure of this specific software within your environment.

  • Code execution vulnerability in network software.
  • High privileges needed; direct internet exposure unlikely.
  • Confirm if affected; assess potential unauthorized access.

Attack Path

How an attacker could exploit the issue

An attacker with high privileges and remote access could exploit this vulnerability by leveraging Dell SmartFabric OS10's failure to properly check the integrity of downloaded code. This allows them to substitute malicious code for legitimate updates, ultimately leading to the execution of arbitrary code on the affected system.

  • Requires high privilege and remote access.
  • Triggered by downloading unverified code.
  • Leads to code execution.

Live Threat

Current exploitation, exposure, and threat context

A high-privileged attacker with remote access could potentially cause the affected system to execute arbitrary code. This could happen when the system's integrity checks fail during code downloads.

  • System integrity and code execution.
  • Code download without integrity check.
  • Unauthorized code execution.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in Dell SmartFabric OS10 Software, which allows for code execution, requires a coordinated response. Infrastructure and platform teams managing the network devices are likely responsible for this operating system. The initial practical move involves identifying all instances of the affected software, confirming their network exposure and criticality, and then engaging with the accountable owner to prioritize remediation efforts.

  • Infrastructure and platform teams should own.
  • Verify network reachability and criticality first.
  • Plan remediation based on risk assessment.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Dell SmartFabric OS10?

Dell SmartFabric OS10 is the specialized network operating system that powers Dell Technologies' data center switches. It provides the software infrastructure used to manage network traffic, automate configurations, and maintain connectivity across high-performance computing environments and enterprise data centers.

What does CWE-494 mean for CVE-2026-63696?

CWE-494, or Download of Code Without Integrity Check, means the software accepts and installs updates or files without verifying their source or authenticity. In this CVE, the lack of these checks allows an attacker to bypass security measures and trick the system into running unauthorized or malicious code instead of legitimate software updates.

How is this vulnerability triggered?

An attacker must already possess high-level administrative credentials and remote access to the switch to initiate the malicious download. The vulnerability is not triggered by standard network traffic or routine operations, but specifically occurs when the system fails to validate code during an update or file download process.

Is my network device at risk?

According to Halo Surface Signal, this software is typically found on infrastructure within internal management segments or data center fabrics, making direct public internet exposure unlikely. Your primary concern is internal access; if an attacker has already compromised a high-privileged account on your network, they could reach these devices.

What should I do first to address this?

Begin by inventorying your environment to locate all instances of Dell SmartFabric OS10. Once identified, confirm which devices are running versions older than 10.6.1.3 and coordinate with your infrastructure team to prioritize the application of official vendor security updates.

References