Dell released patches on October 5 for 18 critical vulnerabilities in its Container Storage Modules (CSM) and Dell System Update (DSU) tools. Two of the flaws carry the maximum CVSS score of 10.0, and five more rate 9.0 or above. No active exploitation has been reported so far, but the company lists no workarounds and is urging immediate upgrades.
The two most severe flaws, CVE-2026-63688 and CVE-2026-63692, both target CSM Authorization. The first is a missing-authentication vulnerability in the storage gRPC server that lets an unauthenticated remote attacker access administrator credentials across all registered arrays. The second affects the authorization proxy and tenant service, and it gives attackers complete administrative control by bypassing authentication entirely.
Four more critical flaws round out the list. CVE-2026-67269, rated 9.9, enables root-level access on Kubernetes cluster nodes. CVE-2026-54472, rated 9.8, exploits hard-coded credentials to forge administrative tokens. CVE-2026-61421, also rated 9.8, exposes a JWT signing secret in an archived component. Additionally, CVE-2026-67273, rated 9.6, grants cluster-wide read access to Kubernetes Secrets. A separate flaw in Dell System Update, CVE-2026-86360, also scores 9.6 and allows remote code execution with root privileges on PowerEdge servers.
The affected products include all CSM versions before 1.18.0, which integrate with Dell PowerStore, PowerScale, PowerFlex, PowerMax, and Unity XT storage systems running on Kubernetes. DSU versions before 2.3.0.0 are also vulnerable.
Security researchers have described the flaws as “a wish list for every ransomware group” because they target the intersection of enterprise storage and container orchestration. While Dell has not linked these flaws to any active campaign, the company noted that its vulnerabilities have historically attracted state-sponsored groups, including Lazarus and UNC6201.
Dell recommends upgrading to CSM version 1.18.0 and DSU version 2.3.0.0 immediately. For CVE-2026-54472 specifically, administrators should also rotate their JWT signing secrets after patching.
