Dell patches critical Container Storage and System Update flaws
Dell patched critical Container Storage Module and System Update flaws, including two CVSS 10.0 bypasses and a CVSS 9.6 path traversal, with no known exploitation.
Dell published DSA-2026-448 for critical Container Storage Module flaws before 1.17.0, fixed in 1.18.0 or later. CVE-2026-63688 and CVE-2026-63692, both CVSS 10.0, let unauthenticated attackers reach CSM Authorization 2.4.0 administrative functions and storage-array credentials; CVE-2026-54472 (CVSS 9.8) uses hard-coded credentials to forge administrative JWTs, and CVE-2026-67269 (CVSS 9.9) can give low-privileged users root on Kubernetes nodes. CSO Online expands the story to 18 critical flaws in CSM and Dell System Update, with CSM before 1.17.0 and DSU before 2.3.0.0 affected and fixes in CSM 1.18.0+ and DSU 2.3.0.0+, and says Dell has no evidence of exploitation. Separately, DSA-2026-324, published Oct. 1, 2026, covers five DSU flaws, led by path-traversal CVE-2026-86360 (CVSS 9.6), which reports say can let a remote unauthenticated attacker access the filesystem and run code as root on PowerEdge servers; the newest account adds that the CVSS vector requires user interaction. Sources disagree on one CVSS 9.6 CSM identifier, listing CVE-2026-67273 or CVE-2026-6727, and differ on CVE-2026-63697 (7.6) and CVE-2026-71168 (7.3), described either as remote execution or as improper certificate validation and another path traversal, while CVE-2026-86361 and CVE-2026-86362 are both CVSS 8.2 local privilege issues. No source reports workarounds or known exploitation; the earliest also advises rotating JWT secrets and reviewing authorization logs and RBAC.
- DSA-2026-448 covers Dell Container Storage Modules before 1.17.0, fixed in 1.18.0 or later; Dell says no workarounds exist.
- CVE-2026-63688 and CVE-2026-63692, both CVSS 10.0, let unauthenticated attackers reach CSM Authorization 2.4.0 admin functions and storage-array credentials.
- CVE-2026-54472 (CVSS 9.8) uses hard-coded credentials to forge administrative JWTs; CVE-2026-67269 (CVSS 9.9) can give low-privileged users root on Kubernetes nodes.
- CSO Online says 18 critical CSM and Dell System Update flaws were disclosed and that Dell has no evidence of exploitation; sources disagree on a CVSS 9.6 CSM id, citing CVE-2026-67273 or CVE-2026-6727.
- DSA-2026-324, published Oct. 1, 2026, covers five Dell System Update flaws before 2.3.0.0 on PowerEdge update workflows, fixed in 2.3.0.0 or later.
- CVE-2026-86360 (CVSS 9.6) is a path traversal that can give a remote unauthenticated attacker filesystem access and root code execution; one report says its CVSS vector requires user interaction.
Coverage timelineoldest first · each row is one article
- · 5d agoCritical Dell Container Storage Flaws Let Unauthenticated Attackers Gain Full Administrative Control
Cyber Security News· 76
Dell patched multiple critical Container Storage Module flaws, including two CVSS 10.0 bugs that let unauthenticated attackers seize administrative control.
- · 2d agoDell patches 18 critical flaws that could hand attackers the keys to storage and Kubernetes
CSO Online· 76
Dell patched 18 critical CSM and DSU flaws, including two CVSS 10 authentication bypasses, with no known exploitation.
- · 2d ago
Vulnerabilities in this storyAll →
- CVE-2026-6368810.0—Unauthenticated Credential Theft in Dell Container Storage Modules (CSM) gRPC Serverpublished · Dell Container Storage Modules (CSM) - csm-authorization-storage gRPC server (CSM Authorization module)+4 related
- CVE-2026-863609.6—Unauthenticated Path Traversal to Root Code Execution in Dell System Updatepublished · Dell System Update (DSU)+4 related