Junglewise Threat Intelligence

CVE-2026-78491: Dell Secure Connect Gateway improper certificate validation

CVE-2026-78491 · Severity: high · CVSS 8.2 · Published 2026-09-09

Technologies: Dell Secure Connect Gateway 5.0 Application, Dell Secure Connect Gateway 5.0 Appliance. Vendors: Dell.

Executive brief

Dell Secure Connect Gateway (SCG) is a remote access appliance used to securely connect users to corporate networks. An improper certificate validation flaw allows unauthenticated attackers with network access to bypass SSL/TLS protections, potentially enabling man-in-the-middle attacks and unauthorized access to the system.

Technical details

The vulnerability is an improper certificate validation issue in Dell SCG 5.0 Appliance (versions prior to 5.36.00.16) and SCG 5.0 Application (versions prior to 5.36.00.00). An unauthenticated attacker with remote network access can exploit this flaw to compromise the integrity of TLS/SSL connections and gain unauthorized access. The vulnerability does not require authentication or user interaction. The attack vector is network-based, and the impact includes integrity compromise and availability disruption (CVSS 8.2: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H). Dell has released patched versions and recommends immediate upgrade.

Affected products

  • Dell Secure Connect Gateway 5.0 Appliance prior to 5.36.00.16
  • Dell Secure Connect Gateway 5.0 Application prior to 5.36.00.00

Timeline

  • 2026-09-09: disclosed

References

Related threats