As noted by Bleeping Computer, Dell has released patches for two critical vulnerabilities affecting its Container Storage Modules (CSM), which are essential for integrating Dell enterprise storage arrays with Kubernetes environments. These flaws, found in the CSM Authorization security module, could allow unauthenticated attackers to gain complete administrative control over storage infrastructure.
The vulnerabilities, tracked as CVE-2026-63688 and CVE-2026-63692, stem from missing authentication for critical functions. Successful exploitation could grant attackers access to administrator credentials and bypass authorization, leading to unauthorized access and manipulation of storage resources across all tenants. Dell also addressed four other critical issues, including gaining root access on cluster nodes and forging authentication tokens. While these specific flaws are not yet flagged as actively exploited, past incidents involving state-sponsored actors exploiting other Dell vulnerabilities highlight the potential risks. For instance, the Lazarus group and a suspected Chinese state-backed group have previously leveraged Dell vulnerabilities for malicious purposes. Dell strongly advises customers to upgrade their Container Storage Modules to version 1.18.0 or later to mitigate these risks.
Source: Bleeping Computer
