1d ago · hacker-news
Dell has disclosed multiple critical vulnerabilities in its Container Storage Modules (CSM) affecting versions prior to 1.17.0, which were patched in version 1.18.0. The most severe flaws include CVE-2026-63688 and CVE-2026-63692, both with a CVSS score of 10.0, enabling unauthenticated remote attackers to gain administrative access to storage infrastructure and Kubernetes clusters. Exploitation of these vulnerabilities could allow full control over storage systems, privilege escalation to root, and unauthorized manipulation of access policies across tenants.