Junglewise Threat Intelligence

CVE-2026-79637: Dell Secure Connect Gateway improper certificate validation

CVE-2026-79637 · Severity: high · CVSS 7.7 · Published 2026-09-09

Technologies: Dell Secure Connect Gateway 5.0 Application, Dell Secure Connect Gateway 5.0 Appliance. Vendors: Dell.

Executive brief

Dell Secure Connect Gateway is a network security appliance and application used to control and monitor remote access to corporate networks. The vulnerability allows unauthenticated attackers to bypass certificate validation checks over the network, potentially enabling man-in-the-middle attacks to intercept sensitive communications or gain unauthorized access to the system.

Technical details

This vulnerability (CVE-2026-79637) is an improper certificate validation flaw in the Secure Connect Gateway SSL/TLS implementation. An unauthenticated attacker with network access can exploit the weak certificate validation logic to bypass certificate checks during remote connections. The attack requires no user interaction, authentication, or local access. By successfully exploiting this, an attacker can establish unauthorized encrypted channels, potentially leading to unauthorized access to the system and interception of sensitive data. Dell released patches addressing this issue in SCG 5.0 Appliance 5.36.00.16 and SCG 5.0 Application 5.36.00.00.

Affected products

  • Dell Secure Connect Gateway 5.0 Appliance prior to 5.36.00.16
  • Dell Secure Connect Gateway 5.0 Application prior to 5.36.00.00

Timeline

  • 2026-09-09: disclosed
  • patched: Patches available: SCG 5.0 Appliance 5.36.00.16 and SCG 5.0 Application 5.36.00.00

References

Related threats