Executive brief
Dell Secure Connect Gateway is a network access control appliance and application used to secure remote connections to corporate networks. An improper certificate validation flaw allows unauthenticated remote attackers to bypass security protections, potentially intercepting or manipulating traffic and gaining unauthorized access to protected systems.
Technical details
CVE-2026-79734 is an improper certificate validation vulnerability in Dell SCG 5.0. An unauthenticated attacker with network access can exploit this to bypass the application's certificate verification mechanism, leading to protection mechanism bypass. The vulnerability affects SCG 5.0 Appliance versions prior to 5.36.00.16 and SCG 5.0 Application versions prior to 5.36.00.00. No special privileges or user interaction are required; the attack can be performed remotely over the network. Patches are available in version 5.36.00.16 (Appliance) and 5.36.00.00 (Application).
Affected products
- Dell Secure Connect Gateway 5.0 Appliance prior to 5.36.00.16
- Dell Secure Connect Gateway 5.0 Application prior to 5.36.00.00
Timeline
- 2026-09-07: disclosed: CVE-2026-79734 published on NVD
- 2026-09-07: advisory: Dell DSA-2026-382 security update released