Junglewise Threat Intelligence

CVE-2026-80135: Dell Secure Connect Gateway improper exception handling bypass

CVE-2026-80135 · Severity: high · CVSS 7.5 · Published 2026-09-07

Technologies: Dell Secure Connect Gateway Application, Dell Secure Connect Gateway Appliance. Vendors: Dell.

Executive brief

Dell Secure Connect Gateway is a remote access and VPN appliance used by enterprises to provide secure connectivity. CVE-2026-80135 is an improper handling of exceptions vulnerability that allows unauthenticated attackers with network access to bypass security protections. Successful exploitation could allow attackers to circumvent intended access controls and compromise system security.

Technical details

CVE-2026-80135 is an improper check or handling of exceptional conditions vulnerability in Dell Secure Connect Gateway (SCG) 5.0. The vulnerability allows unauthenticated remote attackers to bypass protection mechanisms through network access, without requiring authentication or user interaction. The flaw resides in the appliance/application's error handling logic, which fails to properly validate or restrict operations when exceptional conditions occur. Patches are available for affected versions: SCG 5.0 Appliance must be updated to version 5.36.00.16 or later, and SCG 5.0 Application must be updated to version 5.36.00.00 or later.

Affected products

  • Dell Secure Connect Gateway Appliance 5.0 prior to 5.36.00.16
  • Dell Secure Connect Gateway Application 5.0 prior to 5.36.00.00

Timeline

  • 2026-09-07: disclosed: Published on NVD and Dell security advisory DSA-2026-382

References

Related threats