Dell WMS CVE-2026-41120 RCE Exploit Attempt via Anomalous JSON POST
This rule detects potential Remote Code Execution (RCE) exploitation attempts targeting Dell Wyse Management Suite (WMS) by identifying abnormally large POST requests containing JSON payloads directed at specific management paths (/WMS/ or /wyse/). This behavior is indicative of an exploit attempt against CVE-2026-41120.
Suricata

