Junglewise Threat Intelligence

CVE-2026-79965: Dell Secure Connect Gateway external control of critical state data

CVE-2026-79965 · Severity: medium · CVSS 5.3 · Published 2026-09-09

Technologies: Dell Secure Connect Gateway Application, Dell Secure Connect Gateway Appliance. Vendors: Dell.

Executive brief

Dell Secure Connect Gateway (SCG) is a remote access and VPN appliance used to secure corporate network connectivity. This vulnerability allows an unauthenticated attacker with network access to gain unauthorized control over critical system state data, potentially enabling account takeover, credential theft, and lateral movement into protected networks.

Technical details

CVE-2026-79965 is an external control of critical state data vulnerability in Dell SCG 5.0 affecting both appliance and application deployments. The vulnerability allows unauthenticated remote attackers to manipulate critical system state information without proper authorization checks. The attack requires only network reachability to the affected SCG instance and no user interaction or authentication credentials. Successful exploitation enables unauthorized access to the gateway and potential compromise of the entire remote access infrastructure. Dell has released patches for appliance version 5.36.00.16 and application version 5.36.00.00 to remediate this issue.

Affected products

  • Dell Secure Connect Gateway Appliance prior to 5.36.00.16
  • Dell Secure Connect Gateway Application prior to 5.36.00.00

Timeline

  • 2026-09-09: disclosed
  • patched: Appliance version 5.36.00.16 and Application version 5.36.00.00 contain fixes

References

Related threats