TL;DR
Dell patched three flaws in its PowerStore T storage family. The most severe, CVE-2026-67271, scores a CVSS of 9.8. This Dell PowerStore vulnerability lets an unauthenticated attacker trigger denial of service and remote code execution over SMB.
- Product: Dell PowerStore 500T
- Vulnerabilities: 3 flaws (CVE-2026-67271, CVE-2026-70415, CVE-2026-67262)
- Highest severity: 9.8 (Critical · CVSSv3)
- Worst impact: Dell PowerStore SDNAS, contains an Out-of-bounds Write vulnerability in the SMB/CIFS. An...
- Status: No confirmed exploitation yet; patches available
- Action: Update to 5.0.0.2-2761110 or later now
| CVE | CVSS (CVSSv3) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-67271 | 9.8 | CWE-787 | 5.0.0.2-2761110 or later | Not exploited |
| CVE-2026-70415 | 8.1 | CWE-120 | 5.0.0.2-2761110 or later | Not exploited |
| CVE-2026-67262 | 8.1 | CWE-862 | 5.0.0.2-2761110 or later | Not exploited |
Why it matters
PowerStore arrays hold critical enterprise data. A remote takeover there is severe. The top Dell PowerStore vulnerability needs no login and no user interaction. As a result, an exposed system faces high risk.
How the attack works
The critical flaw is an out-of-bounds write in the SDNAS SMB/CIFS service. An attacker sends a specially crafted SMB packet. That packet can crash the service. Notably, the crash persists when automatic restarts are enabled. Dell warns a more capable attacker could turn it into remote code execution.
The advisory lists two more bugs. CVE-2026-70415 (CVSS 8.1) is a buffer copy flaw in NFS/RPC. It can lead to command execution. CVE-2026-67262 (CVSS 8.8) is a missing authorization flaw. It lets a mapped host read or write LUNs it should not reach.
Affected versions
The flaws affect PowerStoreT OS versions before 5.0.0.2-2761110. The list spans many models, from the 500T to the 9200T. Dell’s DSA-2026-330 advisory names each affected product.
Exploitation status and patch steps
Dell reports no in-the-wild exploitation of these flaws. Even so, update without delay. Upgrade to PowerStoreT OS 5.0.0.2-2761110 or later. Until you patch, limit network access to the storage management and data interfaces.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.