Junglewise Threat Intelligence

CVE-2026-79690: Dell Secure Connect Gateway improper certificate validation

CVE-2026-79690 · Severity: low · CVSS 3.7 · Published 2026-09-09

Technologies: Dell Secure Connect Gateway Application, Dell Secure Connect Gateway Appliance. Vendors: Dell.

Executive brief

Dell Secure Connect Gateway (SCG) is a network appliance used to provide secure remote access and gateway functionality for organizations. A flaw in certificate validation allows unauthenticated attackers on the network to bypass security checks and gain unauthorized access to the system. This could enable credential theft, session hijacking, or pivoting to other systems on the corporate network.

Technical details

The vulnerability is an improper certificate validation flaw affecting the authentication and encryption mechanisms in Dell SCG. An unauthenticated attacker with network access can exploit weak certificate validation to intercept or spoof encrypted communications. No authentication is required to trigger the vulnerability, and the attack is performed over the network without user interaction. Successful exploitation leads to unauthorized access and potential compromise of gateway functionality. Dell has released patches in version 5.36.00.16 (Appliance) and 5.36.00.00 (Application).

Affected products

  • Dell Secure Connect Gateway Appliance prior to 5.36.00.16
  • Dell Secure Connect Gateway Application prior to 5.36.00.00

Timeline

  • 2026-09-09: disclosed: CVE-2026-79690 published
  • 2026-09-09: patched: Dell released DSA-2026-382 with patches for SCG 5.36.00.16 (Appliance) and 5.36.00.00 (Application)

References

Related threats