UNC6201 Exploits Dell RecoverPoint Zero-Day: What Security Teams Need to Know
What Security Teams Need to Know In a significant and ongoing cyber-espionage campaign, a sophisticated threat actor has been exploiting a critical zero-day vulnerability in Dell RecoverPoint for Virtual Machines since at least mid-2024. The vulnerability - tracked as CVE-2026-22769 and carrying a CVSSv3.1 score of 10.0 (Critical) - has enabled remote unauthenticated access, root-level persistence, lateral movement, and deployment of custom malware across compromised enterprise environments. This post breaks down the technical details, adversary activity, enterprise impact, and immediate defensive actions organizations should take. What Is CVE-2026-22769? CVE-2026-22769 is a critical vulnerability in Dell RecoverPoint for Virtual Machines (RP4VM) versions prior to 6.0.3.1 HF1. The root cause is the presence of hard-coded credentials within the appliance's Apache Tomcat Manager configuration. An attacker with knowledge of these credentials can authenticate remotely without valid user input, effectively bypassing standard authentication controls. Successful exploitation enables: Unauthenticated remote access Root-level command execution Installation…
