Dell patches 18 critical flaws that could hand attackers the keys to storage and Kubernetes
Dell patched 18 critical CSM and DSU flaws, including two CVSS 10 authentication bypasses, with no known exploitation.
Dell disclosed 18 critical vulnerabilities in Container Storage Modules and Dell System Update that could let attackers bypass authentication, gain root, forge admin tokens, or control storage and Kubernetes clusters. Two flaws, CVE-2026-63688 and CVE-2026-63692, score CVSS 10; others include CVE-2026-67269 (9.9), CVE-2026-54472 (9.8), CVE-2026-6727 (9.6), and path-traversal CVE-2026-86360 (9.6) in DSU. CSM versions before 1.17.0 and DSU before 2.3.0.0 are affected; fixes are CSM 1.18.0 or later and DSU 2.3.0.0 or later, with no workarounds. Dell said it has no evidence of in-the-wild exploitation.