Dell: 18 Vulnerabilities Disclosed Across Multiple Products, Ranging High to Medium Severity
Key findings • 18 vulnerabilities disclosed across multiple Dell products between September 21-24, 2026. • High-severity flaws in Dell ThinOS 10 and Dell Secure Connect Gateway Policy Manager…

Key findings
- 18 vulnerabilities disclosed across multiple Dell products between September 21-24, 2026.
- High-severity flaws in Dell ThinOS 10 and Dell Secure Connect Gateway Policy Manager permit unauthorized access and privilege escalation.
- Vulnerabilities include improper authorization, certificate validation issues, and missing authentication for critical functions.
- Affected products range from endpoint management tools to operating system components.
- Dell has released patches for all disclosed vulnerabilities, with specific version updates recommended.
On September 24, 2026, a batch of 18 vulnerabilities affecting various Dell products was disclosed, spanning a three-day period from September 21 to September 24. These vulnerabilities, ranging in severity from Medium to High, impact critical components such as Dell ThinOS, Dell Trusted Device Client, Dell Rugged Control Center, and Dell Secure Connect Gateway. The disclosures highlight potential risks including unauthorized access, elevation of privileges, and information tampering, underscoring the need for prompt patching and security updates across affected Dell systems.
Several vulnerabilities were identified in Dell ThinOS 10, with CVE-2026-82157 and CVE-2026-81455 posing significant risks. CVE-2026-82157, rated High with a CVSSv3 score of 8.3, involves Improper Certificate Validation, potentially allowing an unauthenticated attacker with adjacent network access to bypass protection mechanisms and gain unauthorized access. Similarly, CVE-2026-81455, also High severity (CVSSv3 8.6), stems from a Missing Authentication for Critical Function, enabling unauthenticated remote attackers to achieve unauthorized access. Both are fixed in SecurityAddon_2605.10.2766_T10.
Dell Secure Connect Gateway (SCG) Policy Manager is affected by multiple vulnerabilities, with CVE-2026-73588 being a critical High severity flaw (CVSSv3 7.4) due to Missing Authentication for Critical Function, allowing remote unauthenticated attackers unauthorized access. Other SCG Policy Manager issues include CVE-2026-73591 (High, 7.5) for Inclusion of Sensitive Information in Source Code, CVE-2026-73589 (Medium, 6.8) for Improper Certificate Validation, CVE-2026-73586 (Medium, 6.4) for Insufficient Session Expiration, CVE-2026-71177 (Medium, 5.4) for Improper Restriction of Rendered UI Layers or Frames, CVE-2026-61413 (Medium, 6.8) for Improper Privilege Management, and CVE-2026-71178 (Low, 3.7) for Use of Non-Canonical URL Paths. Many of these issues are addressed in versions prior to 5.34.00.16, with some also referencing version 5.36.
Dell Trusted Device Client is impacted by CVE-2026-82164 (High, 7.1), an Incorrect Permission Assignment for Critical Resource vulnerability that could lead to information tampering by a local attacker. This is patched in versions prior to 8.1.359.0. Dell Rugged Control Center (RCC) has two vulnerabilities: CVE-2026-81473 (High, 8.1) and CVE-2026-56792 (Medium, 4.4), both related to Improper Authorization, potentially allowing local privilege escalation. These are fixed in versions prior to 5.2.206.
Other affected products include Dell Inventory Collector Client, impacted by CVE-2026-81469 (High, 7.8) for Unquoted Search Path or Element, potentially leading to code execution and privilege elevation, fixed in versions prior to 15.0.0. Dell Command | Monitor (DCM) has CVE-2026-49811 (High, 8.4) for Incorrect Permission Assignment for Critical Resource, allowing privilege escalation, patched in versions prior to 10.13.2. Dell Command | Integration Suite for System Center (CVE-2026-82165, Medium, 5.5) and Dell Command | Intel vPro Out of Band (CVE-2026-82163, Medium, 5.5) both suffer from Incorrect Default Permissions, leading to information disclosure, with fixes in versions prior to 6.7.2 and 4.7.2 respectively. Finally, Dell Command Powershell Provider (DCPP) has CVE-2026-49810 (High, 7.8) for Insertion of Sensitive Information into Log File, patched in versions prior to 2.10.2.
Users of affected Dell products are strongly advised to review the specific CVE details and apply the necessary patches and updates as outlined in Dell's security advisories. The wide range of affected products and vulnerability types emphasizes the importance of maintaining up-to-date systems and applying security fixes promptly to mitigate risks of unauthorized access, data exposure, and system compromise.
The batch of vulnerabilities was disclosed between September 21 and September 24, 2026.
Key vulnerabilities include:
- High-severity flaws in Dell ThinOS 10 (CVE-2026-82157, CVE-2026-81455) allowing unauthorized access.
- Multiple High and Medium severity issues in Dell Secure Connect Gateway Policy Manager (e.g., CVE-2026-73588, CVE-2026-73591).
- Improper Authorization vulnerabilities in Dell Rugged Control Center (CVE-2026-81473, CVE-2026-56792) leading to privilege escalation.
- Incorrect Permission Assignment vulnerabilities in Dell Trusted Device Client (CVE-2026-82164) and Dell Command | Monitor (CVE-2026-49811).
- Patches are available for all disclosed vulnerabilities, with specific version updates provided for each affected product.
CVEs included in this disclosure are: CVE-2026-82164, CVE-2026-82157, CVE-2026-81473, CVE-2026-81455, CVE-2026-56792, CVE-2026-73591, CVE-2026-73589, CVE-2026-73588, CVE-2026-73587, CVE-2026-73586, CVE-2026-71178, CVE-2026-71177, CVE-2026-61413, CVE-2026-81469, CVE-2026-49811, CVE-2026-82165, CVE-2026-82163, CVE-2026-49810.