BTC$85,484+1.97% LTC$70.78+5.63% XMR$542.06+0.66%
TorPortal TorPortalMarkets, mirrors, dark web news
BleepingComputer · Oct 2, 2026 · 2 min read · Original story

Dell asks admins to patch max severity CSM flaws as soon as possible

Dell asks admins to patch max severity CSM flaws as soon as possible

Dell has patched two maximum severity vulnerabilities in the Container Storage Modules (CSM) that connect Dell enterprise storage arrays to Kubernetes environments.

CSM supports Dell's primary storage platforms (PowerStore, PowerScale, PowerFlex, PowerMax, and Unity XT), and it extends the capabilities of the standard Container Storage Interface (CSI) drivers for Kubernetes.

In a security advisory published on Thursday, Dell said that both critical security flaws were found in the Dell CSM Authorization security module and stem from "missing authentication for critical functions" weaknesses.

The first (tracked as CVE-2026-63688) allows unauthenticated remote attackers to access storage backend administrator credentials for all registered storage arrays and bypass authorization to gain full administrative control over the storage infrastructure.

Successful exploitation of the second flaw (CVE-2026-63692), present in the authorization proxy and tenant service, also allows threat actors to gain admin privileges by bypassing authentication controls.

"This vulnerability is considered critical as it enables an unauthenticated attacker to gain complete administrative control over the authorization service, potentially allowing unauthorized access to and manipulation of storage resources across all tenants," Dell warned.

The same day, the company also patched four additional critical-severity Dell CSM security issues that remote attackers can also exploit without privileges to gain root on cluster nodes (CVE-2026-67269), gain administrative access to the CSM Authorization proxy (CVE-2026-54472), forge authentication tokens to gain administrative privileges (CVE-2026-61421), and bypass Kubernetes access controls for cluster-wide read access to Kubernetes Secrets (CVE-2026-67273).

"Dell recommends customers to upgrade at the earliest opportunity," the company added, advising customers to update their container storage modules to version 1.18.0 or later, which patches these flaws.

Dell vulnerabilities exploited in the wild

While Dell has yet to flag these security issues as actively exploited, state-sponsored hackers have abused other Dell vulnerabilities in attacks in recent years.

For instance, the North Korean Lazarus hacking group deployed a Windows rootkit on victims' systems by exploiting an insufficient access control vulnerability (CVE-2021-21551) in the Dell dbutil driver.

More recently, in February, Mandiant and the Google Threat Intelligence Group (GTIG) revealed that a suspected Chinese state-backed hacking group (UNC6201) had been exploiting a maximum-severity hardcoded-credential vulnerability (CVE-2026-22769) in Dell RecoverPoint for Virtual Machines since at least mid-2024 to deploy malware payloads and create hidden network interfaces on VMware ESXi servers.

The security researchers also found overlaps between UNC6201 and the Silk Typhoon Chinese cyberespionage group, known for targeting government agencies with custom Spawnant and Zipline malware in Ivanti zero-day attacks.

Days later, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered government agencies to patch vulnerable Dell systems on their networks within three days.

References in this story

  1. DSA-2026-448: Security Update for Dell Container Storage Modules Multiple Vulnerabilities | Dell US www.dell.com Dell Container Storage Modules remediation is available for Multiple vulnerabilities in third-party that could be exploited by malicious users to compromise the affected system.
  2. Lazarus hackers abuse Dell driver bug using new FudModule rootkit www.bleepingcomputer.com The notorious North Korean hacking group 'Lazarus' was seen installing a Windows rootkit that abuses a Dell hardware driver in a Bring Your Own Vulnerable Driver attack.
  3. Chinese hackers exploiting Dell zero-day flaw since mid-2024 www.bleepingcomputer.com A suspected Chinese state-backed hacking group has been quietly exploiting a critical Dell security flaw in zero-day attacks that started in mid-2024.
  4. Ivanti EPMM flaw exploited by Chinese hackers to breach govt agencies www.bleepingcomputer.com Chinese hackers have been exploiting a remote code execution flaw in Ivanti Endpoint Manager Mobile (EPMM) to breach high-profile organizations worldwide.
  5. Ivanti zero-day attacks infected devices with custom malware www.bleepingcomputer.com Hackers exploiting the critical Ivanti Connect Secure zero-day vulnerability disclosed yesterday installed on compromised VPN appliances new malware called 'Dryhook' and 'Phasejam' that is not currently associated with…
  6. Ivanti Connect Secure zero-days exploited to deploy custom malware www.bleepingcomputer.com Hackers have been exploiting the two zero-day vulnerabilities in Ivanti Connect Secure disclosed this week since early December to deploy multiple families of custom malware for espionage purposes.
  7. CISA orders feds to patch actively exploited Dell flaw within 3 days www.bleepingcomputer.com The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered government agencies to patch their systems within three days against a maximum-severity Dell vulnerability that has been under active exploitation…

← Back to all news