{"id":9902,"date":"2026-10-06T01:25:24","date_gmt":"2026-10-06T01:25:24","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=9902"},"modified":"2026-10-06T01:25:24","modified_gmt":"2026-10-06T01:25:24","slug":"dell-patches-18-critical-flaws-that-could-hand-attackers-the-keys-to-storage-and-kubernetes","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=9902","title":{"rendered":"Dell patches 18 critical flaws that could hand attackers the keys to storage and Kubernetes"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p class=\"wp-block-paragraph\">Dell\u2019s security team has had a busy week.<\/p>\n<p class=\"wp-block-paragraph\">The company has announced a slew of Common Vulnerabilities and Exposures (CVEs) impacting its <a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-us\/000515771\/dsa-2026-448-security-update-for-dell-container-storage-modules-multiple-vulnerabilities\">Dell Container Storage Modules<\/a> (CSM) and <a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-us\/000515843\/dsa-2026-324-security-update-for-dell-system-update-dsu-vulnerabilities\">Dell System Update<\/a> (DSU).<\/p>\n<p class=\"wp-block-paragraph\">Disclosed by Dell in two security notices, these critical vulnerabilities could allow unauthenticated attackers to \u201ccompletely bypass\u201d authentication controls, gain root access, manipulate storage resources, or forge admin tokens. Two of the flaws are rated 10, the most critical severity rating on the Common Vulnerability Scoring System (CVSS) scale, and five others are rated 9 and above.<\/p>\n<p class=\"wp-block-paragraph\">Customers are advised to upgrade as soon as possible, although Dell said it has no evidence that any of the flaws are being actively exploited yet.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThis advisory reads like a wish list for every ransomware group on the planet,\u201d said <a href=\"https:\/\/www.linkedin.com\/in\/dbshipley\/\">David Shipley<\/a>, CEO of Beauceron Security. \u201cThese are security holes in many organizations\u2019 crown jewels: Storage and the link between storage and Kubernetes clusters.\u201d<\/p>\n<h2 class=\"wp-block-heading\">Giving attackers full control<\/h2>\n<p class=\"wp-block-paragraph\">CSM and DSU are two critical Dell offerings; CSMs are <a href=\"https:\/\/www.csoonline.com\/article\/4229623\/rolling-the-cyber-dice-with-open-source-and-open-weight-ai-models.html\">open-source software extensions<\/a> that connect to Kubernetes, while the DSU is a general deployment tool for updating packages in PowerEdge servers.<\/p>\n<p class=\"wp-block-paragraph\">The 18 newly discovered CVEs could allow both local and adjacent network attackers to gain root-level access, escalate privileges, execute arbitrary code, tamper with information and role-based access control (RBAC), and perform remote code execution (RCE).<\/p>\n<p class=\"wp-block-paragraph\">Dell DSU versions prior to 2.3.0.0 are impacted; versions 2.3.0.0 or later have been remediated. Dell CSM versions prior to 1.17.0 are impacted, and version\u00a0 1.18.0 or later have been remediated. There are no workarounds or mitigations; customers must update to fixed versions.<\/p>\n<h2 class=\"wp-block-heading\">Troubling flaws<\/h2>\n<p class=\"wp-block-paragraph\">Many of the <a href=\"https:\/\/www.csoonline.com\/article\/4168484\/your-refresh-plan-has-a-cve-blind-spot.html\">security flaws<\/a> are quite troubling: the 10-rated CVE-2026-63688 in CSM, for instance, documents the lack of authentication for critical functions in the <em>csm-authorization-storage<\/em> gRPC server. Attackers could exploit it to gain access to backend storage administrator credentials for registered storage arrays across all five supported Dell storage product families. The vulnerability is critical because it could enable \u201cfull administrative control\u201d over storage infrastructure, Dell reported.<\/p>\n<p class=\"wp-block-paragraph\">CVE-2026-63692 in CSM, also rated 10, similarly reports the lack of authentication controls for critical functions in the <a href=\"https:\/\/www.csoonline.com\/article\/4227199\/stolen-ai-credentials-feed-growing-llm-proxy-economy.html\">authorization proxy<\/a> and tenant service. Threat actors could potentially gain \u201ccomplete administrative control\u201d over the authorization service, Dell said. The 9.9-rated CVE-2026-67269 in the CSM\u2019s core controller system, meanwhile, could allow a low-privilege remote attacker to gain root-level access and \u201ccompletely compromise all nodes\u201d in the Kubernetes cluster.<\/p>\n<p class=\"wp-block-paragraph\">Dell has also patched 9.8-rated CVE-2026-54472 in CSM, which could allow threat actors to forge cryptographically valid administrative tokens and gain unauthorized administrative access to the CSM authorization proxy; and 9.6-rated CVE-2026-6727 in CSM, which could give attackers the ability to effectively bypass Kubernetes access controls, gain cluster-wide read access, and create cluster-scoped access controls.<\/p>\n<p class=\"wp-block-paragraph\">The 9.6-rated path traversal vulnerability CVE-2026-86360 in DSU, meanwhile, could allow threat actors to execute arbitrary code with root privileges. This would enable \u201ccomplete compromise\u201d of the vulnerable app as well as the underlying operating system, Dell said.<\/p>\n<h2 class=\"wp-block-heading\">Not seen in the wild \u2014 yet<\/h2>\n<p class=\"wp-block-paragraph\">Dell said there have so far been no reports of these vulnerabilities being exploited in the wild, however, nation-state threat actors have previously targeted vulnerabilities in Dell infrastructure, noted <a href=\"https:\/\/www.infotech.com\/profiles\/bob-wilson\">Bob Wilson<\/a>, cybersecurity advisor at Info-Tech Research Group.<\/p>\n<p class=\"wp-block-paragraph\">\u201cI would interpret \u2018not seen in the wild\u2019 as \u2018not seen in the wild <em>yet<\/em>,\u2019\u201d he said.<\/p>\n<p class=\"wp-block-paragraph\">While it might seem to be a lot of disclosures at once, Dell typically releases patch information in batches. And because these vulnerabilities affect infrastructure rather than a front-facing application, they tend to be deprioritized or overlooked during patch-management cycles, Wilson observed.<\/p>\n<p class=\"wp-block-paragraph\">Ultimately, organizations using Dell storage products and PowerEdge servers could be compromised by any threat actor with a remote access path to these devices, he pointed out. \u201cAny data stored on those devices could also be exposed \u2014 potentially, nearly everything,\u201d Wilson said.<\/p>\n<p class=\"wp-block-paragraph\">As well as patching, he advised impacted enterprises to:<\/p>\n<p>Rotate backend administrator credentials, along with CSM authorization credentials and tokens.<\/p>\n<p>Ensure that affected systems are on segmented networks and that traffic to them is restricted to only what is absolutely necessary.<\/p>\n<p>Ensure all systems using DSU are patched and addressed, including Azure Stack HCI and ESXi environments as well as standard Linux and Windows systems.<\/p>\n<p class=\"wp-block-paragraph\">And, he added, \u201cremain on heightened alert for signs of intrusion.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Furthermore, Shipley advised, if your logs show anything odd, rotate credentials for good measure, because \u201cit is only a matter of hours, at most, days, before we see working PoC exploit code.\u201d<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>Dell\u2019s security team has had a busy week. The company has announced a slew of Common Vulnerabilities and Exposures (CVEs) impacting its Dell Container Storage Modules (CSM) and Dell System Update (DSU). Disclosed by Dell in two security notices, these critical vulnerabilities could allow unauthenticated attackers to \u201ccompletely bypass\u201d authentication controls, gain root access, manipulate [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":9903,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-9902","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9902"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9902"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9902\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/9903"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9902"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9902"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9902"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}