Junglewise Threat Intelligence

CVE-2026-78492: Dell Secure Connect Gateway improper certificate validation

CVE-2026-78492 · Severity: high · CVSS 7.4 · Published 2026-09-09

Technologies: Dell Secure Connect Gateway Application, Dell Secure Connect Gateway Appliance. Vendors: Dell.

Executive brief

Dell Secure Connect Gateway (SCG) is a VPN appliance and application used to securely connect remote users to corporate networks. This vulnerability allows an unauthenticated remote attacker to bypass certificate validation, potentially enabling man-in-the-middle attacks to intercept or manipulate encrypted communications, leading to data theft or session hijacking.

Technical details

This vulnerability is an improper certificate validation flaw in Dell SCG 5.0 versions prior to 5.36.00.16 (appliance) and 5.36.00.00 (application). An unauthenticated attacker with network access can exploit insufficient certificate validation checks to perform man-in-the-middle attacks. The vulnerability requires no authentication or user interaction, and the attack vector is purely network-based. Exploitation could lead to unauthorized access, interception of sensitive communications, or impersonation of legitimate SCG endpoints. Dell has released patches in versions 5.36.00.16 and later.

Affected products

  • Dell Secure Connect Gateway Appliance prior to 5.36.00.16
  • Dell Secure Connect Gateway Application prior to 5.36.00.00

Timeline

  • 2026-09-09: disclosed

References

Related threats