Dell discloses 18 security vulnerabilities in enterprise storage and server-update tools, two rated CVSS 10.0
What happened
Dell's security team disclosed a batch of 18 CVEs affecting Container Storage Modules (CSM) and Dell System Update (DSU), products widely used to manage Kubernetes-connected storage and deploy firmware to PowerEdge servers. Two flaws scored a maximum 10.0 on CVSS: CVE-2026-63688, a missing authentication control in the CSM Authorization storage gRPC server that could let an unauthenticated attacker access backend admin credentials across all five supported storage families, and CVE-2026-63692, which could allow bypassing auth controls for admin access across tenants. Another flaw, CVE-2026-86360, is a path traversal in DSU allowing remote code execution with root privileges. Security researchers called the advisory a 'wish list for every ransomware group' and warned proof-of-concept exploit code could appear within hours or days.
Why it matters & what’s next are part of Pro, along with the audio summary.
Start your free 14-day trialWho’s affected
- Dell Technologies (DELL) directly — enterprise infrastructure products CSM and Dell System Update are the vulnerable lines. Read-through to enterprise IT/security software and storage vendors broadly, but no specific named spillover.
Sources
