Dell Secure Connect Gateway: 25 Vulnerabilities Including Hard-Coded Credentials Disclosed Together
Dell disclosed 25 vulnerabilities in Secure Connect Gateway 5.0, including critical hard-coded credential flaws, on September 9, 2026.

Key findings
- 25 vulnerabilities disclosed in Dell Secure Connect Gateway 5.0 on September 9, 2026.
- High-severity flaws (CVSSv3 7.5) due to hard-coded credentials in CVE-2026-79950, CVE-2026-79740, CVE-2026-79738.
- Multiple OS Command Injection and Command Injection vulnerabilities present.
- Affected versions are prior to SCG 5.0 Appliance 5.36.00.16 and Application 5.36.00.00.
- Patched versions are available; immediate update recommended.
On September 9, 2026, Dell disclosed a significant batch of 25 vulnerabilities affecting its Secure Connect Gateway (SCG) 5.0 product. The vulnerabilities, disclosed within a three-hour window, span a range of severity levels, from Low to High, with the most critical issues stemming from the use of hard-coded credentials. These flaws could allow unauthenticated remote attackers to gain unauthorized access or expose sensitive information.
Several vulnerabilities fall under the category of OS Command Injection, including CVE-2026-79947, CVE-2026-79945, and CVE-2026-79689. These issues, exploitable by low-privileged local attackers, could lead to arbitrary command execution on the affected appliance or application. Additionally, CVE-2026-79741 and CVE-2026-79941 represent Command Injection vulnerabilities that could be exploited by unauthenticated remote attackers.
A notable cluster of high-severity vulnerabilities, CVE-2026-79950, CVE-2026-79740, and CVE-2026-79738, are all attributed to the use of hard-coded credentials. These flaws carry a CVSSv3 score of 7.5 and could permit unauthenticated remote attackers to access sensitive information. Another related vulnerability, CVE-2026-79731, also involves the use of hard-coded credentials, though with a medium severity rating.
Other vulnerabilities include Cross-Site Scripting (XSS) flaws like CVE-2026-79946, which could enable script injection, and Improper Certificate Validation issues such as CVE-2026-79736, CVE-2026-79732, and CVE-2026-79690, potentially allowing protection mechanism bypass. Least Privilege Violation vulnerabilities, CVE-2026-79944 and CVE-2026-79693, could lead to unauthorized access for high-privileged local attackers.
The entire batch of vulnerabilities affects Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00. All disclosed vulnerabilities have been addressed in version 5.36.00.16 for the appliance and 5.36.00.00 for the application. Users are strongly advised to update to the patched versions to mitigate the risks associated with these security flaws.
This coordinated disclosure highlights the importance of timely patching for Dell Secure Connect Gateway users. The variety of vulnerabilities, particularly the command injection and hard-coded credential flaws, underscores the potential impact on system integrity and data confidentiality. Organizations utilizing Dell SCG should prioritize applying the available updates to protect their environments.