Dell asks admins to patch max severity CSM flaws as soon as possible

Dell asks admins to patch max severity CSM flaws as soon as possible
Dell has patched six critical vulnerabilities in Container Storage Modules that connect its enterprise storage arrays to Kubernetes environments, including flaws that could let unauthenticated attackers gain full administrative control. The issues affect Dell CSM Authorization, proxy, and tenant services, and Dell urges customers to upgrade to version 1.18.0 or later as soon as possible. #DellCSM #CVE202663688 #CVE202663692 #CVE202667269 #CVE202654472 #CVE202661421 #CVE202667273

Keypoints

  • Dell fixed two maximum-severity flaws in Container Storage Modules for Kubernetes.
  • CVE-2026-63688 can expose storage backend administrator credentials and bypass authorization.
  • CVE-2026-63692 can let attackers gain admin privileges through the authorization proxy and tenant service.
  • Four more critical CSM bugs can enable root access, token forgery, and access to Kubernetes Secrets.
  • Dell recommends updating Container Storage Modules to version 1.18.0 or later immediately.

Read More: https://www.bleepingcomputer.com/news/security/new-max-severity-dell-csm-flaws-give-hackers-admin-privileges/