Junglewise Threat Intelligence

CVE-2026-79967: Dell Secure Connect Gateway improper certificate validation

CVE-2026-79967 · Severity: medium · CVSS 5.6 · Published 2026-09-09

Technologies: Dell Secure Connect Gateway Application, Dell Secure Connect Gateway Appliance. Vendors: Dell.

Executive brief

Dell Secure Connect Gateway is a network security appliance and application used to provide secure remote access and connectivity. The vulnerability allows an unauthenticated attacker with remote access to bypass certificate validation protections, potentially enabling man-in-the-middle attacks and unauthorized system access without proper credential verification.

Technical details

CVE-2026-79967 is an improper certificate validation vulnerability in Dell SCG 5.0 Appliance (prior to 5.36.00.16) and Dell SCG 5.0 Application (prior to 5.36.00.00). The vulnerability allows an unauthenticated attacker with network access to exploit insufficient certificate validation checks, enabling a protection mechanism bypass. An attacker can intercept and manipulate network communications without proper validation of the server's identity. The issue affects the TLS/SSL certificate verification logic in the SCG platform. Patches are available in SCG 5.0 Appliance version 5.36.00.16 and Application version 5.36.00.00 or later.

Affected products

  • Dell Secure Connect Gateway Appliance 5.0 prior to 5.36.00.16
  • Dell Secure Connect Gateway Application 5.0 prior to 5.36.00.00

Timeline

  • 2026-09-09: disclosed

References

Related threats