[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f5nx-w2TGiq9CicskGsu3ReItTxC-iT4Jye7D52y0png":3},{"article":4,"iocs":52},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":34,"category":35,"article_tags":39},"9b6467ea-ec30-4008-b5ac-3443bc69c52e","Dell asks admins to patch max severity CSM flaws as soon as possible","dell-asks-admins-to-patch-max-severity-csm-flaws-as-soon-as-possible-778774","Dell has patched two maximum severity vulnerabilities in the Container Storage Modules (CSM) that connect Dell enterprise storage arrays to Kubernetes environments. [...]","Dell has released patches for two maximum severity vulnerabilities in its Container Storage Modules (CSM) that integrate Dell enterprise storage arrays with Kubernetes environments. These flaws, found in the CSM Authorization module, allow unauthenticated remote attackers to gain administrative control over storage infrastructure and access sensitive credentials. Dell also patched four other critical CSM vulnerabilities, urging customers to update to version 1.18.0 or later.","Dell releases patches for critical Container Storage Modules (CSM) vulnerabilities.","Dell asks admins to patch max severity CSM flaws as soon as possible By Sergiu Gatlan October 2, 2026 08:37 AM 0 Dell has patched two maximum severity vulnerabilities in the Container Storage Modules (CSM) that connect Dell enterprise storage arrays to Kubernetes environments. CSM supports Dell's primary storage platforms (PowerStore, PowerScale, PowerFlex, PowerMax, and Unity XT), and it extends the capabilities of the standard Container Storage Interface (CSI) drivers for Kubernetes. In a security advisory published on Thursday, Dell said that both critical security flaws were found in the Dell CSM Authorization security module and stem from \"missing authentication for critical functions\" weaknesses. The first (tracked as CVE-2026-63688) allows unauthenticated remote attackers to access storage backend administrator credentials for all registered storage arrays and bypass authorization to gain full administrative control over the storage infrastructure. Successful exploitation of the second flaw (CVE-2026-63692), present in the authorization proxy and tenant service, also allows threat actors to gain admin privileges by bypassing authentication controls. \"This vulnerability is considered critical as it enables an unauthenticated attacker to gain complete administrative control over the authorization service, potentially allowing unauthorized access to and manipulation of storage resources across all tenants,\" Dell warned. The same day, the company also patched four additional critical-severity Dell CSM security issues that remote attackers can also exploit without privileges to gain root on cluster nodes (CVE-2026-67269), gain administrative access to the CSM Authorization proxy (CVE-2026-54472), forge authentication tokens to gain administrative privileges (CVE-2026-61421), and bypass Kubernetes access controls for cluster-wide read access to Kubernetes Secrets (CVE-2026-67273). \"Dell recommends customers to upgrade at the earliest opportunity,\" the company added, advising customers to update their container storage modules to version 1.18.0 or later, which patches these flaws. Dell vulnerabilities exploited in the wild While Dell has yet to flag these security issues as actively exploited, state-sponsored hackers have abused other Dell vulnerabilities in attacks in recent years. For instance, the North Korean Lazarus hacking group deployed a Windows rootkit on victims' systems by exploiting an insufficient access control vulnerability (CVE-2021-21551) in the Dell dbutil driver. More recently, in February, Mandiant and the Google Threat Intelligence Group (GTIG) revealed that a suspected Chinese state-backed hacking group (UNC6201) had been exploiting a maximum-severity hardcoded-credential vulnerability (CVE-2026-22769) in Dell RecoverPoint for Virtual Machines since at least mid-2024 to deploy malware payloads and create hidden network interfaces on VMware ESXi servers. The security researchers also found overlaps between UNC6201 and the Silk Typhoon Chinese cyberespionage group, known for targeting government agencies with custom Spawnant and Zipline malware in Ivanti zero-day attacks. Days later, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered government agencies to patch vulnerable Dell systems on their networks within three days. Build your security blueprint for AI-powered attacks Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed. Save your seat Related Articles: TeamViewer urges users to patch severe flaws “as soon as possible”GitLab urges users to patch max severity path traversal flawOver 36,000 exposed Plex servers vulnerable to recent flawsPlex warns users to patch security vulnerabilities immediatelyCISA orders urgent patching of actively exploited Zimbra flaw","https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fnew-max-severity-dell-csm-flaws-give-hackers-admin-privileges\u002F","https:\u002F\u002Fwww.bleepstatic.com\u002Fcontent\u002Fhl-images\u002F2026\u002F05\u002F14\u002FDell.jpg","2026-10-02T12:37:40+00:00","2026-10-02T14:01:04.19837+00:00",8,[18,21,24,27,30,32],{"name":19,"type":20},"Container Storage Modules (CSM)","product",{"name":22,"type":23},"Dell","vendor",{"name":25,"type":26},"Kubernetes","technology",{"name":28,"type":29},"Lazarus Group","threat_actor",{"name":31,"type":29},"UNC6201",{"name":33,"type":29},"Silk Typhoon","80544778-fabb-4dcd-aa35-17492e5dcf4f",{"id":34,"icon":36,"name":37,"slug":38},null,"Vulnerabilities","vulnerabilities",[40,42,47],{"category":41},{"id":34,"icon":36,"name":37,"slug":38},{"category":43},{"id":44,"icon":36,"name":45,"slug":46},"c70f3a41-2f0c-4608-870d-b8cbcd8be076","Cloud Security","cloud-security",{"category":48},{"id":49,"icon":36,"name":50,"slug":51},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[53,57,60,63,66,69,72,75],{"type":54,"value":55,"context":56},"cve","CVE-2026-63688","Missing authentication for critical functions in Dell CSM Authorization module.",{"type":54,"value":58,"context":59},"CVE-2026-63692","Missing authentication for critical functions in Dell CSM Authorization proxy and tenant service.",{"type":54,"value":61,"context":62},"CVE-2026-67269","Remote attackers can gain root on cluster nodes.",{"type":54,"value":64,"context":65},"CVE-2026-54472","Remote attackers can gain administrative access to the CSM Authorization proxy.",{"type":54,"value":67,"context":68},"CVE-2026-61421","Remote attackers can forge authentication tokens to gain administrative privileges.",{"type":54,"value":70,"context":71},"CVE-2026-67273","Remote attackers can bypass Kubernetes access controls for cluster-wide read access to Kubernetes Secrets.",{"type":54,"value":73,"context":74},"CVE-2021-21551","Dell dbutil driver vulnerability exploited by Lazarus Group.",{"type":54,"value":76,"context":77},"CVE-2026-22769","Dell RecoverPoint for Virtual Machines hardcoded-credential vulnerability exploited by suspected Chinese state-backed group."]