Skip to content
TECH CEO Daily
CybersecuritySecurity Alert

Dell patches two CVSS 10.0 Container Storage Modules flaws and a critical System Update bug

Six critical bugs in the software linking Kubernetes to Dell storage arrays could let attackers take admin control; Dell says to upgrade to CSM 1.18.0, with no workarounds.

By · Editor

· 3 min read · Fact-checked

The 60-second brief

  • 1Dell fixed six critical Container Storage Modules flaws; CVE-2026-63688 and CVE-2026-63692 are rated the maximum 10.0.
  • 2The worst could let an unauthenticated attacker obtain storage admin credentials for all registered arrays.
  • 3A separate critical Dell System Update flaw, CVE-2026-86360, could allow root code execution; upgrade to 2.3.0.0.

The news

Dell Technologies (DELL) has released fixes for six critical vulnerabilities in Dell Container Storage Modules (CSM), two of them rated the maximum 10.0 on the CVSS severity scale. CSM is software that connects Kubernetes container clusters to Dell's PowerStore, PowerScale, PowerFlex, PowerMax and Unity XT storage systems, according to BleepingComputer.

The first maximum-severity flaw, CVE-2026-63688, is a missing authentication check in a gRPC server, The Hacker News reported. BleepingComputer said it lets unauthenticated attackers obtain storage administrator credentials for all registered arrays, giving full administrative control of the storage. The second, CVE-2026-63692, is missing authentication in the CSM authorization proxy and tenant service. Dell called it critical because it lets an unauthenticated attacker gain complete administrative control, as reported by BleepingComputer.

The other four are also rated critical, according to The Hacker News: CVE-2026-67269 (9.9), which lets a low-privilege attacker get root on cluster nodes; CVE-2026-54472 (9.8), hard-coded credentials that allow forging admin tokens; CVE-2026-61421 (9.8), a hard-coded cryptographic key used to forge authentication tokens; and CVE-2026-67273 (9.6), a template injection flaw that can expose sensitive information and allow unauthorized changes to role-based access controls.

Dell's advisory, DSA-2026-448, first published October 1 and revised October 5, lists all CSM versions before 1.18.0 as affected and version 1.18.0 or later as the fix. The Hacker News reported that Dell urges customers to apply the updates and rotate any JWT signing secrets, the keys used to sign login tokens, and that there are no workarounds other than updating. Neither outlet reported active exploitation.

Separately, Dell patched a critical path traversal flaw, CVE-2026-86360, in Dell System Update (DSU), a command-line tool used to deploy updates to servers. Dell said an unauthenticated attacker with remote access could potentially exploit it to gain filesystem access, and BleepingComputer reported it could lead to arbitrary code execution with root privileges. Dell says to update DSU to version 2.3.0.0 or later. Dell fixed four more high-severity DSU bugs in the same release.

The numbers

Critical CSM flaws fixed
6
Highest CVSS score
10.0 (two flaws)
Fixed CSM version
1.18.0 or later
Fixed Dell System Update version
2.3.0.0 or later

Why CEOs should care

For CISOs and infrastructure leaders, these bugs sit at a dangerous point: the layer that hands Kubernetes workloads access to enterprise storage. An attacker who obtains storage admin credentials for every registered array could, in principle, reach the data behind many applications at once. Ask your platform team whether CSM is deployed, which version, and whether its services are reachable from untrusted networks.

Because there are no workarounds, the only fix is the upgrade. Plan it as an emergency change, then rotate JWT signing secrets and any storage admin credentials CSM held, as hard-coded credentials and keys mean tokens may have been forgeable before the patch. Review Kubernetes audit logs and storage admin activity for unexpected access.

For CFOs and boards, no exploitation has been reported, but BleepingComputer noted that state-sponsored groups have exploited other Dell flaws in past campaigns. The cost of a fast patch cycle is small next to an incident affecting core storage. Also confirm that server teams update Dell System Update to 2.3.0.0, since a root-level flaw in a patching tool is a direct path into servers.

The bigger picture

The CSM flaws fit a familiar pattern in infrastructure software: missing authentication and hard-coded secrets in components that were built for convenience inside trusted networks. As Kubernetes connects more directly to storage, backup and identity systems, those helper services become high-value targets, and enterprises should inventory them with the same care as the arrays themselves.

What’s next

Watch for Dell advisory updates and any addition of these CVEs to CISA's Known Exploited Vulnerabilities catalog, which would signal active attacks and set deadlines for US federal agencies.

What “Fact-checked” means

Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.

What we checked
Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
How
A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
Who
The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, . A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
If something is wrong
“Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error

How we fact-check →

Companies in this story

Dell TechnologiesKubernetesContainer Storage ModulesDell System UpdateVulnerability

Earlier coverage of Dell

All Dell coverage →

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

About this story. Researched from primary sources whenever they are available and fact-checked before publication.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards

Follow Tech CEO Daily on Facebook for the day’s top stories in your feed.

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Monday to Saturday, 7 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.