Close Menu
NCIJ Network NCIJ Network
    What's Hot

    The hill I will die on: not everything is a ‘girl’ thing – stop gendering and infantilising it all | Elle Hunt

    October 3, 2026

    Flavio Bolsonaro: In the name of the father, sons, and holy ideology

    October 3, 2026

    Best Mosquito Repellents for Your Yard: What Works and What Doesn’t (2026)

    October 3, 2026
    Facebook X (Twitter) Instagram
    Trending
    • The hill I will die on: not everything is a ‘girl’ thing – stop gendering and infantilising it all | Elle Hunt
    • Flavio Bolsonaro: In the name of the father, sons, and holy ideology
    • Best Mosquito Repellents for Your Yard: What Works and What Doesn’t (2026)
    • Dell asks admins to patch max severity CSM flaws as soon as possible
    • Ethereum Now Lets You Pay for AI Without Revealing Who You Are
    • Worcestershire woman fought to get menopause diagnosis for years
    • Flydubai co-pilot attacked captain with axe, UAE official says
    • Paramount and Warner Bros. Discovery to become Skydance
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Saturday, October 3
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Dell asks admins to patch max severity CSM flaws as soon as possible

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKOctober 3, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Dell has patched two maximum severity vulnerabilities in the Container Storage Modules (CSM) that connect Dell enterprise storage arrays to Kubernetes environments.

    CSM supports Dell’s primary storage platforms (PowerStore, PowerScale, PowerFlex, PowerMax, and Unity XT), and it extends the capabilities of the standard Container Storage Interface (CSI) drivers for Kubernetes.

    In a security advisory published on Thursday, Dell said that both critical security flaws were found in the Dell CSM Authorization security module and stem from “missing authentication for critical functions” weaknesses.

    The first (tracked as CVE-2026-63688) allows unauthenticated remote attackers to access storage backend administrator credentials for all registered storage arrays and bypass authorization to gain full administrative control over the storage infrastructure.

    Successful exploitation of the second flaw (CVE-2026-63692), present in the authorization proxy and tenant service, also allows threat actors to gain admin privileges by bypassing authentication controls.

    “This vulnerability is considered critical as it enables an unauthenticated attacker to gain complete administrative control over the authorization service, potentially allowing unauthorized access to and manipulation of storage resources across all tenants,” Dell warned.

    The same day, the company also patched four additional critical-severity Dell CSM security issues that remote attackers can also exploit without privileges to gain root on cluster nodes (CVE-2026-67269), gain administrative access to the CSM Authorization proxy (CVE-2026-54472), forge authentication tokens to gain administrative privileges (CVE-2026-61421), and bypass Kubernetes access controls for cluster-wide read access to Kubernetes Secrets (CVE-2026-67273).

    “Dell recommends customers to upgrade at the earliest opportunity,” the company added, advising customers to update their container storage modules to version 1.18.0 or later, which patches these flaws.

    Dell vulnerabilities exploited in the wild

    While Dell has yet to flag these security issues as actively exploited, state-sponsored hackers have abused other Dell vulnerabilities in attacks in recent years.

    For instance, the North Korean Lazarus hacking group deployed a Windows rootkit on victims’ systems by exploiting an insufficient access control vulnerability (CVE-2021-21551) in the Dell dbutil driver.

    More recently, in February, Mandiant and the Google Threat Intelligence Group (GTIG) revealed that a suspected Chinese state-backed hacking group (UNC6201) had been exploiting a maximum-severity hardcoded-credential vulnerability (CVE-2026-22769) in Dell RecoverPoint for Virtual Machines since at least mid-2024 to deploy malware payloads and create hidden network interfaces on VMware ESXi servers.

    The security researchers also found overlaps between UNC6201 and the Silk Typhoon Chinese cyberespionage group, known for targeting government agencies with custom Spawnant and Zipline malware in Ivanti zero-day attacks.

    Days later, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered government agencies to patch vulnerable Dell systems on their networks within three days.


    article image

    Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

    Save your seat

    admins asks CSM Dell flaws Max patch severity
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs

    CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV

    The EDR blind spot: 3 ways browser attacks evade endpoint telemetry

    GitLab warns of critical RCE vulnerability in AI Gateway service

    Warlock ransomware breach SharePoint in water, telecom operator attacks

    Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    The hill I will die on: not everything is a ‘girl’ thing – stop gendering and infantilising it all | Elle Hunt

    October 3, 2026

    Flavio Bolsonaro: In the name of the father, sons, and holy ideology

    October 3, 2026

    Best Mosquito Repellents for Your Yard: What Works and What Doesn’t (2026)

    October 3, 2026

    Dell asks admins to patch max severity CSM flaws as soon as possible

    October 3, 2026
    Latest Posts

    Lime bikes hurtling around the city: is this the revenge of a priced-out generation? | Andy Beckett

    August 8, 2026

    Clarity Act Delayed Until September, Trump Praises Bitcoin

    August 8, 2026

    North Carolina Ports confirms cyberattack disrupting operations

    August 8, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    The hill I will die on: not everything is a ‘girl’ thing – stop gendering and infantilising it all | Elle Hunt

    October 3, 2026

    Flavio Bolsonaro: In the name of the father, sons, and holy ideology

    October 3, 2026

    Best Mosquito Repellents for Your Yard: What Works and What Doesn’t (2026)

    October 3, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.