Dell Technologies Building
– Getty Images

Dell released various patches for critical flaws affecting its storage and server suites.

With almost 20 CVEs in total, Dell’s patches concern its Dell Container Storage Modules (CSM) and Dell System Update (DSU), with the latter a deployment tool designed for Dell's PowerEdge server line.

Dell CSM users were advised of 13 CVEs in total, six of which are in the high to critical range. CVE-2026-63688 and CVE-2026-63692 for example were rated the maximum severity score of 10.0. The former flagged a missing authentication for critical function which could lead to “unauthorized access to storage backend administrator credentials for all registered storage arrays.”

With a similar flaw, the latter could allow an unauthenticated attacker with remote access via an elevation of privileges.

Users were advised to upgrade to CSM Version 1.18.0 or later.

On the DSU side, five bugs were flagged. The most critical of these, CVE-2026-86360, provides another remote control execution (RCE) opportunity via a path traversal vulnerability.

“This vulnerability is considered critical because it can be leveraged by an unauthenticated attacker to execute arbitrary code with root privileges. Successful exploitation may allow complete compromise of the vulnerable application and underlying operating system,” Dell warned, recommending customers upgrade to Dell DSU Version 2.3.0.0 or later.