Smart Money Hub Free money tools · save your results with a free account
▼ Negative DELL Listen · Pro

Dell discloses 18 security vulnerabilities in enterprise storage and server-update tools, two rated CVSS 10.0

What happened

Dell's security team disclosed a batch of 18 CVEs affecting Container Storage Modules (CSM) and Dell System Update (DSU), products widely used to manage Kubernetes-connected storage and deploy firmware to PowerEdge servers. Two flaws scored a maximum 10.0 on CVSS: CVE-2026-63688, a missing authentication control in the CSM Authorization storage gRPC server that could let an unauthenticated attacker access backend admin credentials across all five supported storage families, and CVE-2026-63692, which could allow bypassing auth controls for admin access across tenants. Another flaw, CVE-2026-86360, is a path traversal in DSU allowing remote code execution with root privileges. Security researchers called the advisory a 'wish list for every ransomware group' and warned proof-of-concept exploit code could appear within hours or days.

Why it matters & what’s next are part of Pro, along with the audio summary.

Start your free 14-day trial

Who’s affected

  • Dell Technologies (DELL) directly — enterprise infrastructure products CSM and Dell System Update are the vulnerable lines. Read-through to enterprise IT/security software and storage vendors broadly, but no specific named spillover.

Sources

smbtech.au

Introducing Paycheck Paradox PRO

Every story is free to read. Pro adds why it matters, what to watch next and audio summaries of every move, hourly.

Start your free 14-day trial

See all the latest moves → · Everything from October 9

News summary for information only, not investment advice. Audio summaries are read by an AI voice.

Smart Money Hub · build Oct 9, 2026, 2:02 PM EDT