Junglewise Threat Intelligence

CVE-2026-78489: Dell Secure Connect Gateway improper certificate validation

CVE-2026-78489 · Severity: medium · CVSS 5.9 · Published 2026-09-09

Technologies: Dell Secure Connect Gateway Application, Dell Secure Connect Gateway Appliance. Vendors: Dell.

Executive brief

Dell Secure Connect Gateway is a remote access appliance and application used to provide secure connectivity to corporate networks. An improper certificate validation vulnerability allows unauthenticated remote attackers to bypass security protections, potentially enabling man-in-the-middle attacks or unauthorized access to sensitive systems and data.

Technical details

The vulnerability is an improper certificate validation flaw in Dell SCG 5.0 versions prior to 5.36.00.16 (Appliance) and 5.36.00.00 (Application). An unauthenticated attacker with network access can exploit this by sending crafted requests that bypass certificate validation checks, leading to authentication and integrity protection bypass. The root cause appears to be insufficient validation of X.509 certificate properties during TLS/SSL handshakes. Patches are available in versions 5.36.00.16 and later for the Appliance, and 5.36.00.00 and later for the Application.

Affected products

  • Dell Secure Connect Gateway Appliance prior to 5.36.00.16
  • Dell Secure Connect Gateway Application prior to 5.36.00.00

Timeline

  • 2026-09-09: disclosed

References

Related threats