Dell's 18 Flaws Open Storage to Attackers
Dell has patched 18 CVEs in its storage and update tools, including two maximum-severity flaws with no workarounds.
Dell's security team disclosed 18 Common Vulnerabilities and Exposures affecting its Container Storage Modules and System Update tool, including two flaws rated 10 on the CVSS scale. The company says it has no evidence of exploitation so far, but the flaws could hand attackers administrative control over storage infrastructure and Kubernetes clusters.
What Dell Is Fixing
Dell published two security notices covering the flaws. The first affects Dell Container Storage Modules (CSM), which are open-source extensions that connect to Kubernetes. The second affects Dell System Update (DSU), a deployment tool for updating packages on PowerEdge servers. According to Dell, the vulnerabilities could allow unauthenticated attackers to "completely bypass" authentication controls, gain root access, manipulate storage resources, or forge admin tokens.
Dell's advisories state that customers should upgrade as soon as possible. The company said it has no evidence that any of the flaws are being actively exploited yet.
The Two Maximum-Severity Bugs
The most severe flaw, CVE-2026-63688, carries a CVSS rating of 10. It documents the lack of authentication for critical functions in the csm-authorization-storage gRPC server. Dell says attackers could exploit it to access backend storage administrator credentials for registered storage arrays across all five supported Dell storage product families, enabling "full administrative control" over storage infrastructure.
A second 10-rated flaw, CVE-2026-63692, reports missing authentication controls for critical functions in the authorization proxy and tenant service. Dell warns that threat actors could gain "complete administrative control" over the authorization service.
Other Critical Flaws in the Batch
Beyond the two 10-rated issues, several other flaws carry high severity scores. The 9.9-rated CVE-2026-67269 in the CSM core controller system could let a low-privilege remote attacker gain root-level access and "completely compromise all nodes" in a Kubernetes cluster.
Dell also patched 9.8-rated CVE-2026-54472 in CSM, which could allow attackers to forge cryptographically valid administrative tokens and gain unauthorized administrative access to the CSM authorization proxy. A 9.6-rated flaw, CVE-2026-6727, could let attackers bypass Kubernetes access controls, gain cluster-wide read access, and create cluster-scoped access controls.
The 9.6-rated path traversal vulnerability CVE-2026-86360 in DSU could allow attackers to execute arbitrary code with root privileges, enabling "complete compromise" of the vulnerable app and the underlying operating system, according to Dell.
Affected Versions and Remediation
Dell DSU versions prior to 2.3.0.0 are impacted; versions 2.3.0.0 or later have been remediated. Dell CSM versions prior to 1.17.0 are impacted, and version 1.18.0 or later have been remediated. Dell says there are no workarounds or mitigations; customers must update to fixed versions.
For more details, see the Dell security notices for Container Storage Modules and System Update.
Why the Flaws Matter
David Shipley, CEO of Beauceron Security, said the advisory reads like a wish list for ransomware groups. "These are security holes in many organizations' crown jewels: Storage and the link between storage and Kubernetes clusters," he said.
These are security holes in many organizations' crown jewels: Storage and the link between storage and Kubernetes clusters.
— David Shipley, CEO of Beauceron Security
Bob Wilson, cybersecurity advisor at Info-Tech Research Group, said that while Dell reported no exploitation, nation-state threat actors have previously targeted vulnerabilities in Dell infrastructure. "I would interpret 'not seen in the wild' as 'not seen in the wild yet,'" Wilson said.
Wilson added that because these vulnerabilities affect infrastructure rather than a front-facing application, they tend to be deprioritized or overlooked during patch-management cycles.
Recommended Mitigations
Beyond patching, Wilson advised impacted enterprises to take specific steps:
- Rotate backend administrator credentials, along with CSM authorization credentials and tokens.
- Ensure that affected systems are on segmented networks and that traffic to them is restricted to only what is absolutely necessary.
- Ensure all systems using DSU are patched and addressed, including Azure Stack HCI and ESXi environments as well as standard Linux and Windows systems.
He also advised organizations to "remain on heightened alert for signs of intrusion."
Shipley added that if logs show anything odd, organizations should rotate credentials for good measure. "It is only a matter of hours, at most, days, before we see working PoC exploit code," he said.
The Bottom Line
For organizations running Dell storage products and PowerEdge servers, the flaws could allow compromise by any threat actor with a remote access path to these devices. Wilson noted that any data stored on those devices could also be exposed, potentially nearly everything.
Dell has released fixed versions for both CSM and DSU, and customers should update immediately given the lack of workarounds. The absence of in-the-wild exploitation offers a window to act, but Wilson's warning that it is "yet" suggests the window may close. Security teams should prioritize these patches, rotate credentials, and segment affected systems to reduce the blast radius if exploits emerge.
Sources
- CSO Online Original source
- Dell Container Storage Modules Also reporting
- Dell System Update Also reporting
Continue Reading
Atlassian's unpatched datacenter flaw
Atlassian warns datacenter users to patch a 9.3-rated arbitrary file access flaw or pull instances off the internet.
Exchange Flaw Opens Mailboxes to Insiders
Microsoft pushed out-of-band fixes for CVE-2026-96940, a high-severity Exchange Server authorization flaw rated 8.8.
Google Pauses OSS Bug Bounty Submissions
Google has temporarily stopped accepting product vulnerability reports for its OSS VRP, citing a surge in automated, mostly invalid submissions.