Skip to content
Security Alerts

CVE-2026-67271: Remote code execution via SMB in Dell PowerStore

An out-of-bounds write in SMB/CIFS handling in Dell PowerStore SDNAS. A crafted SMB packet causes a crash that persists despite automatic restarts...

Summary

ParameterValue
CVE IDCVE-2026-67271
Alert SourceGitHub Advisory - Critical Vulnerability
CVE Publication Year2026
Date Published2026-08-18
VendorDell
ProductPowerStore
CVSS Score9.8 (critical)
EPSS ScoreNo data
CISA KEVNo
RansomwareNot confirmed

Vulnerability Description

Dell PowerStore SDNAS, contains an Out-of-bounds Write vulnerability in the SMB/CIFS. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Denial of service and Remote execution. This is a Critical vulnerability as a remote user could send a specially crafted SMB packet and cause a crash, that is persistent in case automatic restarts are enabled. Additionally, a more sophisticated attacker could use the same vulnerability for Remote Code executi…

Required Actions

  1. Apply the Dell update per advisory DSA-2026-330 for Dell PowerStore T. This is the only source of the fix.
  2. Note the nature of the failure: it is persistent despite automatic restarts. A single packet can therefore take the array offline for a period requiring manual intervention — and the array typically serves many systems at once. Assess this vulnerability in business-continuity terms, not only data confidentiality.
  3. Restrict SMB/CIFS access to the array to known server segments only. Exposing SMB beyond management and server networks has no justification here.
  4. Verify whether your disaster recovery plan covers a PowerStore outage scenario. If backups are stored on the same array, this alert is also a signal to change your backup architecture.

Who Is Affected?

Organizations using Dell PowerStore arrays with SDNAS enabled (file sharing over SMB/CIFS). This typically covers environments where PowerStore serves file shares to users or application servers.

Sources


Need help securing your systems? nFlo team offers vulnerability management and 24/7 SOC services. Contact us.

Learn More

Share:

Talk to an expert

Have questions about this topic? Get in touch with our specialist.

Sales Representative
Grzegorz Gnych

Grzegorz Gnych

Sales Representative

Response within 24 hours
Free consultation
Individual approach

Providing your phone number will speed up contact.

Want to Reduce IT Risk and Costs?

Book a free consultation - we respond within 24h

Response in 24h Free quote No obligations

Or download free guide:

Download NIS2 Checklist