Junglewise Threat Intelligence

CVE-2026-79736: Dell Secure Connect Gateway improper certificate validation

CVE-2026-79736 · Severity: low · CVSS 3.7 · Published 2026-09-09

Technologies: Dell Secure Connect Gateway Application, Dell Secure Connect Gateway Appliance. Vendors: Dell.

Executive brief

Dell Secure Connect Gateway is a secure remote access appliance used to provide VPN and secure connectivity to corporate networks. An improper certificate validation vulnerability allows unauthenticated remote attackers to bypass security controls and gain unauthorized access to the system, potentially compromising the integrity of connections and enabling man-in-the-middle attacks.

Technical details

This vulnerability is an improper certificate validation flaw in Dell Secure Connect Gateway (SCG) versions 5.0 prior to 5.36.00.16 (appliance) and 5.36.00.00 (application). An unauthenticated attacker with network access can exploit this by bypassing SSL/TLS certificate validation controls, enabling potential man-in-the-middle attacks or session hijacking. The vulnerability requires no user interaction or authentication, though exploit complexity is listed as high. Attackers can achieve unauthorized access to the system. Patches are available in SCG 5.36.00.16 (appliance) and 5.36.00.00 (application).

Affected products

  • Dell Secure Connect Gateway Appliance prior to 5.36.00.16
  • Dell Secure Connect Gateway Application prior to 5.36.00.00

Timeline

  • 2026-09-09: disclosed: Published in DSA-2026-382 security advisory
  • 2026-09-09: patched: Patches available in versions 5.36.00.16 (appliance) and 5.36.00.00 (application)

References

Related threats