> IT-Sentinel.com

// Cybersecurity & IT News Aggregator - Real-time Threat Intelligence Feed

NEWS CVE
← messages.back_to_articles

> Dell patches 18 critical flaws that could hand attackers the keys to storage and Kubernetes

[SOURCE] CSO Online [DATE: 06/10/2026 01:25] [LANGUAGE: EN]
Dell patches 18 critical flaws that could hand attackers the keys to storage and Kubernetes
Dell’s security team has had a busy week. The company has announced a slew of Common Vulnerabilities and Exposures (CVEs) impacting its Dell Container Storage Modules (CSM) and Dell System Update (DSU). Disclosed by Dell in two security notices, these critical vulnerabilities could allow unauthenticated attackers to “completely bypass” authentication controls, gain root access, manipulate storage resources, or forge admin tokens. Two of the flaws are rated 10, the most critical severity rating on the Common Vulnerability Scoring System (CVSS) scale, and five others are rated 9 and above. Customers are advised to upgrade as soon as possible, although Dell said it has no evidence that any of the flaws are being actively exploited yet. “This advisory reads like a wish list for every ransomware group on the planet,” said David Shipley, CEO of Beauceron Security. “These are security holes in many organizations’ crown jewels: Storage and the link between storage and Kubernetes clusters.” Giving attackers full control CSM and DSU are two critical Dell offerings; CSMs are open-source software extensions that connect to Kubernetes, while the DSU is a general deployment tool for updating packages in PowerEdge servers. The 18 newly discovered CVEs could allow both local and adjacent network attackers to gain root-level access, escalate privileges, execute arbitrary code, tamper with information and role-based access control (RBAC), and perform remote code execution (RCE). Dell DSU versions prior to 2.3.0.0 are impacted; versions 2.3.0.0 or later have been remediated. Dell CSM versions prior to 1.17.0 are impacted, and version  1.18.0 or later have been remediated. There are no workarounds or mitigations; customers must update to fixed versions. Troubling flaws Many of the security flaws are quite troubling: the 10-rated CVE-2026-63688 in CSM, for instance, documents the lack of authentication for critical functions in the csm-authorization-storage gRPC server. Attackers could exploit it to gain access to backend storage administrator credentials for registered storage arrays across all five supported Dell storage product families. The vulnerability is critical because it could enable “full administrative control” over storage infrastructure, Dell reported. CVE-2026-63692 in CSM, also rated 10, similarly reports the lack of authentication controls for critical functions in the authorization proxy and tenant service. Threat actors could potentially gain “complete administrative control” over the authorization service, Dell said. The 9.9-rated CVE-2026-67269 in the CSM’s core controller system, meanwhile, could allow a low-privilege remote attacker to gain root-level access and “completely compromise all nodes” in the Kubernetes cluster. Dell has also patched 9.8-rated CVE-2026-54472 in CSM, which could allow threat actors to forge cryptographically valid administrative tokens and gain unauthorized administrative access to the CSM authorization proxy; and 9.6-rated CVE-2026-6727 in CSM, which could give attackers the ability to effectively bypass Kubernetes access controls, gain cluster-wide read access, and create cluster-scoped access controls. The 9.6-rated path traversal vulnerability CVE-2026-86360 in DSU, meanwhile, could allow threat actors to execute arbitrary code with root privileges. This would enable “complete compromise” of the vulnerable app as well as the underlying operating system, Dell said. Not seen in the wild — yet Dell said there have so far been no reports of these vulnerabilities being exploited in the wild, however, nation-state threat actors have previously targeted vulnerabilities in Dell infrastructure, noted Bob Wilson, cybersecurity advisor at Info-Tech Research Group. “I would interpret ‘not seen in the wild’ as ‘not seen in the wild yet,’” he said. While it might seem to be a lot of disclosures at once, Dell typically releases patch information in batches. And because these vulnerabilities affect infrastructure rather than a front-facing application, they tend to be deprioritized or overlooked during patch-management cycles, Wilson observed. Ultimately, organizations using Dell storage products and PowerEdge servers could be compromised by any threat actor with a remote access path to these devices, he pointed out. “Any data stored on those devices could also be exposed — potentially, nearly everything,” Wilson said. As well as patching, he advised impacted enterprises to: Rotate backend administrator credentials, along with CSM authorization credentials and tokens. Ensure that affected systems are on segmented networks and that traffic to them is restricted to only what is absolutely necessary. Ensure all systems using DSU are patched and addressed, including Azure Stack HCI and ESXi environments as well as standard Linux and Windows systems. And, he added, “remain on heightened alert for signs of intrusion.” Furthermore, Shipley advised, if your logs show anything odd, rotate credentials for good measure, because “it is only a matter of hours, at most, days, before we see working PoC exploit code.”
[messages.read_original_source] →