Skip to content
Dell CSM Vulnerabilities Allow Remote Admin Access to Kubernetes

Dell CSM Vulnerabilities Allow Remote Admin Access to Kubernetes

First seen 4 Oct 2026, 18:01 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 4, 2026 at 19:00 UTC
  • •Critical vulnerabilities in Dell CSM allow unauthenticated remote access.
  • •Immediate patching is required for all CSM versions prior to 1.18.0.
  • •No evidence of exploitation has been reported as of October 2026.

Dell has disclosed multiple vulnerabilities in its Container Storage Modules (CSM) affecting Kubernetes environments. The most severe flaws, with a CVSS score of 10.0, enable unauthenticated remote attackers to gain full administrative control over storage infrastructure. These vulnerabilities include CVE-2026-63688 and CVE-2026-63692, both allowing attackers to bypass authentication and access backend credentials. Other significant vulnerabilities include CVE-2026-67269, CVE-2026-54472, and CVE-2026-61421, which also pose serious risks to Kubernetes clusters. As of October 2026, there is no evidence of public exploitation or proof-of-concept code for these vulnerabilities, but immediate patching is recommended. The affected systems include Dell's PowerStore, PowerScale, PowerFlex, PowerMax, and Unity XT, with all CSM versions prior to 1.18.0 being vulnerable.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2021-05-04
CVE-2021-21551 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-10-04
Dell discloses critical CSM vulnerabilities
Dell announced multiple critical vulnerabilities in its Container Storage Modules affecting Kubernetes environments, urging immediate patching.
www.dell.com
2026-10-04
Rescana reports on vulnerabilities
Rescana detailed the vulnerabilities in Dell CSM, highlighting the severity and potential impact on Kubernetes environments.
Rescana

More articles in this cluster (4)

Following this threat?

Track Lazarus Group, Dell and CVE-2021-21551 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which versions of CSM are affected?
All versions of Dell Container Storage Modules prior to 1.18.0 are affected.
Is there any evidence of exploitation?
As of October 2026, there is no evidence of public exploitation or proof-of-concept code for these vulnerabilities.
What should organizations do?
Organizations should immediately apply patches to mitigate the risks associated with these vulnerabilities.