Dell patches 18 critical flaws that could hand attackers the keys to storage and Kubernetes
Summary
Dell disclosed 18 critical vulnerabilities in its Container Storage Modules (CSM, software extensions that connect to Kubernetes, a system for managing containerized applications) and System Update tool that could let attackers bypass authentication, gain root access (complete control of a system), and manipulate storage resources. Two vulnerabilities have the highest severity rating of 10 on the CVSS (Common Vulnerability Scoring System, a 0-10 scale measuring how serious a vulnerability is), with five others rated 9 or above, and Dell reports no evidence of active exploitation yet.
Solution / Mitigation
Dell CSM versions prior to 1.17.0 are affected; customers must upgrade to version 1.18.0 or later. Dell DSU versions prior to 2.3.0.0 are affected; customers must upgrade to version 2.3.0.0 or later. Dell stated there are no workarounds or mitigations; customers must update to these fixed versions.
Classification
Related Issues
CVE-2026-63086: text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compat
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
Original source: https://www.csoonline.com/article/4230923/dell-patches-18-critical-flaws-that-could-hand-attackers-the-keys-to-storage-and-kubernetes.html
First tracked: October 6, 2026 at 02:01 AM
Classified by LLM (prompt v3) · confidence: 75%