Dell has disclosed 18 critical security vulnerabilities affecting its Container Storage Modules and System Update software, with two flaws receiving the highest possible severity rating of 10 on the Common Vulnerability Scoring System scale. The company announced the Common Vulnerabilities and Exposures in two security notices this week, warning that the flaws could enable unauthenticated attackers to bypass authentication controls entirely, obtain root access, manipulate storage resources, or create administrative tokens. The vulnerabilities target storage and server management infrastructure used to connect Kubernetes clusters and update PowerEdge servers.
Two vulnerabilities earned perfect 10 severity scores, while five additional flaws scored 9 or higher. CVE-2026-63688 in Container Storage Modules documents missing authentication for critical functions in the csm-authorization-storage gRPC server, allowing attackers to access backend storage administrator credentials for registered storage arrays across all five supported Dell storage product families. CVE-2026-63692, also rated 10, identifies absent authentication controls for critical functions in the authorization proxy and tenant service. The 9.9-rated CVE-2026-67269 in the core controller system could grant a low-privilege remote attacker root-level access to completely compromise all nodes in a Kubernetes cluster. Other high-severity flaws include CVE-2026-54472, which could let threat actors forge cryptographically valid administrative tokens, and CVE-2026-86360 in Dell System Update, a path traversal vulnerability enabling arbitrary code execution with root privileges. Container Storage Modules versions prior to 1.17.0 are affected, with version 1.18.0 or later containing fixes. Dell System Update versions prior to 2.3.0.0 are impacted, and versions 2.3.0.0 or later have been remediated.
The company said it has no evidence of active exploitation yet, though customers are advised to upgrade as soon as possible. Dell reported that the vulnerabilities could enable "full administrative control" over storage infrastructure and "complete administrative control" over the authorization service. The flaws could also enable "complete compromise" of vulnerable applications as well as underlying operating systems, according to the company. No workarounds or mitigations exist; customers must update to fixed versions.
The vulnerabilities pose severe risks because they affect infrastructure rather than front-facing applications, meaning they tend to be deprioritized or overlooked during patch-management cycles, according to cybersecurity experts cited in Dell's disclosure. Organizations using Dell storage products and PowerEdge servers could be compromised by any threat actor with a remote access path to these devices, potentially exposing nearly everything stored on those systems. The 18 newly discovered flaws could allow both local and adjacent network attackers to gain root-level access, escalate privileges, execute arbitrary code, tamper with information and role-based access control, and perform remote code execution. Because Container Storage Modules are open-source software extensions that connect to Kubernetes, and Dell System Update is a general deployment tool for updating packages in PowerEdge servers, the flaws represent security holes in many organizations' most critical systems.
Dell recommends that impacted enterprises rotate backend administrator credentials along with Container Storage Modules authorization credentials and tokens, ensure affected systems are on segmented networks with traffic restricted to only what's absolutely necessary, and ensure all systems using Dell System Update are patched, including Azure Stack HCI and ESXi environments as well as standard Linux and Windows systems. Security experts quoted in the disclosure advised organizations to remain on heightened alert for signs of intrusion and to rotate credentials if logs show anything unusual, warning that working proof-of-concept exploit code could emerge within hours or days. The threat landscape for infrastructure vulnerabilities remains particularly acute, as enterprise storage and Kubernetes orchestration systems represent attractive targets for ransomware operators seeking to encrypt or exfiltrate sensitive data at scale. Organizations that delay patching these systems may find themselves exposed to attacks that leverage multiple vulnerabilities in sequence, compounding the risk beyond what any single flaw might suggest in isolation.

