Rescana Dell CSM Vulnerabilities Allow Remote Admin Access to Kubernetes
Article Content
- •Critical vulnerabilities in Dell CSM allow unauthenticated remote access.
- •Immediate patching is required for all CSM versions prior to 1.18.0.
- •No evidence of exploitation has been reported as of October 2026.
Dell has disclosed multiple vulnerabilities in its Container Storage Modules (CSM) affecting Kubernetes environments. The most severe flaws, with a CVSS score of 10.0, enable unauthenticated remote attackers to gain full administrative control over storage infrastructure. These vulnerabilities include CVE-2026-63688 and CVE-2026-63692, both allowing attackers to bypass authentication and access backend credentials. Other significant vulnerabilities include CVE-2026-67269, CVE-2026-54472, and CVE-2026-61421, which also pose serious risks to Kubernetes clusters. As of October 2026, there is no evidence of public exploitation or proof-of-concept code for these vulnerabilities, but immediate patching is recommended. The affected systems include Dell's PowerStore, PowerScale, PowerFlex, PowerMax, and Unity XT, with all CSM versions prior to 1.18.0 being vulnerable.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track Lazarus Group, Dell and CVE-2021-21551 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which versions of CSM are affected?
Is there any evidence of exploitation?
What should organizations do?
Continue Reading
Bitget Suffers $388M Hack Attributed to North Korean Lazarus Group On September 24, 2026, Bitget reported a significant security breach resulting in the theft of approximately $388 million from its hot and warm wallets. The attackers exploited a vulnerability in a third-party security product to gain internal access credentials and issued fraudulent withdrawal commands. Bitget's cold…