← back

CVE-2026-63695

CRITICAL · 9.8
hype MIXED · 62 hack

Vendor patched urgently; no PoC/KEV yet; real vuln but exploitation status unclear.

What: Session fixation vulnerability in Dell SmartFabric OS10 prior to 10.6.1.3 allowing unauthenticated remote session theft (CVSS 9.8 CRITICAL).

Why it matters: Dell has released a patch same-day (10.6.1.3); CRITICAL severity and unauthenticated remote access vector drive urgent triage. No KEV listing yet or public PoC observed in posts, but patch availability and vendor advisory confirm real vulnerability requiring immediate deployment.

Where it's seen: Social posts reference Dell's patched version and urge SmartFabric OS10 switch updates; chatter emphasizes severity and remediation path rather than exploitation details or working exploits.

RISK: CRITICAL — Unauthenticated remote session theft in network infrastructure; patch available same-day publication.

Generated by claude-haiku-4-5 from public posts and authoritative metadata. AI can make mistakes — verify against vendor advisories before acting. 9/15/2026, 5:53:08 PM

Description

Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Session Fixation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Session theft.

CVSS 3.1 breakdown

Exploitability 3.9 · Impact 5.9
vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack vector
Network
Complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Weaknesses