Dell has released security updates for Container Storage Modules (CSM), the software that links Dell enterprise storage arrays to Kubernetes environments. Both The Hacker News and BleepingComputer report that the flaws are critical and should be patched immediately, but they differ in scope: BleepingComputer highlights two maximum-severity vulnerabilities, while The Hacker News details six distinct CVEs affecting CSM versions before 1.17.0.
Among the most severe are CVE-2026-63688 and CVE-2026-63692, both rated CVSS 10.0. The first lets an unauthenticated remote attacker obtain storage backend administrator credentials for all registered storage arrays; the second allows an unauthenticated network attacker to bypass authentication and gain administrative privileges on the authorization service. Dell says these enable complete administrative control over storage infrastructure across all supported storage product families.
Other flaws include CVE-2026-67269 (CVSS 9.9), which lets a low-privilege attacker escalate to root on Kubernetes cluster nodes via a single custom resource submission, and CVE-2026-54472 and CVE-2026-61421, which involve hard-coded credentials or cryptographic keys that can be used to forge administrative tokens. A sixth issue, CVE-2026-67273, allows privilege escalation and RBAC tampering, giving cluster-wide read access to Kubernetes Secrets.
Dell states there are no workarounds or mitigations other than upgrading to CSM 1.18.0, and recommends rotating JWT signing secrets. Given Dell's history of actively exploited vulnerabilities, administrators should apply the update as soon as possible.