Dell Patches Six Critical Flaws in Container Storage Modules for Kubernetes
Dell has addressed six vulnerabilities in its Container Storage Modules (CSM), the software suite that connects Dell storage arrays to Kubernetes clusters. Two of the flaws received the highest possible CVSS score of 10.0, enabling remote attackers to gain administrative control without any authentication.
The first critical issue, CVE-2026-63688, stems from missing authentication on the gRPC server within the storage authorization component. An unauthenticated remote attacker can retrieve administrator credentials for every registered storage backend array.
The second 10.0-rated vulnerability, CVE-2026-63692, involves the absence of authentication in both the authorization proxy and the tenant service. Successful exploitation grants complete administrative control over the very service responsible for managing access controls.
A third high-severity flaw, CVE-2026-67269 (CVSS 9.9), results from improper privilege management in the custom resource reconciler. A low-privileged attacker can submit a single malicious resource definition and escalate privileges to root on all nodes, reaching every device in the cluster.
Two additional issues rated 9.8 originate from embedded secrets in the code. CVE-2026-54472 contains hardcoded credentials inside the authorization module, while CVE-2026-61421 exposes the private key used to sign JWT tokens, allowing attackers to forge valid authentication credentials.
The final vulnerability, CVE-2026-67273 (CVSS 9.6), resides in the template engine and permits reading Kubernetes secrets across the entire cluster as well as creating cluster-scoped permissions.
All versions prior to 1.17.0 are affected. The fixes are included in version 1.18.0. No alternative mitigations are available. Dell strongly advises rotating all JWT signing keys after the update, as the previous keys should be treated as publicly known.
Related articles
Critical Sandbox Bypass Flaw in GitLab AI Gateway Enables Remote Command Execution
GitLab has released patches for a critical vulnerability in its GitLab AI Gateway component that allows authenticated users to bypass sandbox restrictions and execute arbitrary commands. The flaw, tracked as CVE-2026-90970, resides in the custom flow prompt template processing of the Duo Agent Platform and carries a CVSS v3.1 base score of 9.9. Self-hosted deployments are affected, while GitLab’s own hosted AI Gateway service has already been updated. The company urges immediate upgrades to versions 19.4.1, 19.3.2, or 19.2.4. The vulnerability can be triggered under specific conditions by users with access to the Duo Agent Platform through crafted flow configurations.
WebPros Releases Critical Patches for Three Vulnerabilities in cPanel & WHM
WebPros International has published security updates addressing three critical vulnerabilities in its cPanel & WHM hosting management platform. All three issues received the highest severity rating of Critical. The flaws include CVE-2026-93698, an input validation weakness in the Multilang adminbin component that could allow root-level operating system command execution. Two additional stored cross-site scripting vulnerabilities were also fixed, one of which is CVE-2026-93697 affecting the Mass Modify Accounts interface in WHM. Successful exploitation of the XSS flaws could let low-privileged accounts hijack administrator sessions. The updates were made available on September 29, 2026, and carry CVSS v3.0 base scores reaching 9.9.
Top Cybersecurity Stories: SharePoint Exploits Warned by US Authorities, Citrix and WordPress Flaws Lead Weekly Rankings
Security NEXT has published its weekly ranking of the most viewed articles from September 27 to October 3, 2026, highlighting critical vulnerability disclosures and confirmed exploitation cases. US authorities issued warnings about active exploitation of five vulnerabilities affecting SharePoint and WordPress. Citrix NetScaler received multiple vulnerability advisories with two flaws already confirmed as exploited in the wild. Apple released iOS 26.7.1 to address vulnerabilities potentially used in targeted attacks against specific individuals. Other notable incidents include a personal data breach at Times Car car-sharing service and a ransomware attack impacting Keio Electric Railway operations.
Google Releases Chrome Update Fixing 11 Vulnerabilities Including Critical WebGL Flaw
Google has issued an update for its Chrome browser that addresses 11 security vulnerabilities across Windows, macOS, and Linux platforms. The release includes Chrome 154.0.8037.98 and 154.0.8037.97 for Windows and macOS, along with version 154.0.8037.97 for Linux. One vulnerability, CVE-2026-103628, received a Critical rating due to an out-of-bounds memory write in WebGL that was originally reported in August. Nine additional issues rated High severity affect components such as FileSystem, Compositing, Skia, FedCM, SVG, MediaStream, and WebRTC, including a buffer overflow tracked as CVE-2026-103631. The update also resolves a type confusion flaw in the V8 scripting engine and one Medium-severity issue. Google plans a gradual rollout over the coming days and weeks.