Dell Secure Connect Gateway: 25 Vulnerabilities Disclosed Together, Ranging from Command Injection to Info Disclosure
Key findings • Dell Secure Connect Gateway 5.0 impacted by 25 vulnerabilities disclosed on September 7, 2026. • High-severity flaws include OS command injection, missing authentication, and i…

Key findings
- Dell Secure Connect Gateway 5.0 impacted by 25 vulnerabilities disclosed on September 7, 2026.
- High-severity flaws include OS command injection, missing authentication, and improper certificate validation.
- Vulnerabilities span information disclosure, privilege escalation, and unauthorized access.
- Affected versions: SCG 5.0 Appliance < 5.36.00.16 and Application < 5.36.00.00.
- Patches are available; prompt update to version 5.36.00.16/5.36.00.00 is recommended.
On September 7, 2026, Dell disclosed a significant batch of 25 vulnerabilities affecting its Secure Connect Gateway (SCG) 5.0 product. These vulnerabilities, disclosed within a three-hour window, span a range of severity levels, including several high-severity flaws, and impact both the SCG appliance and application versions prior to 5.36.00.16 and 5.36.00.00, respectively. The sheer volume and variety of these flaws underscore a critical security posture for users of this product.
Several vulnerabilities center around improper certificate validation, including CVE-2026-80125, CVE-2026-79639, CVE-2026-79644, CVE-2026-79642, CVE-2026-79734, and CVE-2026-80164. These flaws could allow unauthenticated remote attackers to gain unauthorized access. Additionally, OS command injection vulnerabilities, CVE-2026-80127 and CVE-2026-78488, pose a significant risk, with CVE-2026-80127 potentially allowing a high-privileged attacker remote access to execute commands.
Another group of vulnerabilities relates to authentication and authorization weaknesses. CVE-2026-79645 and CVE-2026-78480, both rated high severity, involve missing authentication for critical functions, enabling unauthenticated remote attackers to achieve unauthorized access. Improper privilege management, as seen in CVE-2026-80166, could allow unauthenticated local attackers to elevate their privileges. Furthermore, CVE-2026-80128 and CVE-2026-80170 highlight improper authentication and use of hard-coded credentials, respectively, which could lead to bypasses of protection mechanisms.
Information disclosure is a recurring theme, with vulnerabilities such as CVE-2026-80176 (plaintext storage of passwords), CVE-2026-80167 and CVE-2026-80057 (use of hard-coded cryptographic keys), CVE-2026-80058 (cleartext storage of sensitive information), and CVE-2026-80056 (insertion of sensitive information into log files). These issues could be exploited by low-privileged local attackers to expose sensitive data. Path traversal vulnerabilities, including CVE-2026-80131, CVE-2026-80130, and CVE-2026-80129, also present risks, with CVE-2026-80131 potentially leading to remote execution.
The consistent affected versions across all disclosed CVEs are Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00. Dell has released patches, and users are strongly advised to update to version 5.36.00.16 for the appliance and 5.36.00.00 for the application to mitigate these risks.
This extensive disclosure highlights the importance of timely patching and security diligence for Dell Secure Connect Gateway users. The variety of attack vectors, from command injection to information disclosure and authentication bypasses, necessitates a comprehensive review of security configurations and prompt application of vendor-supplied updates. Users should prioritize addressing these vulnerabilities to protect their systems from potential compromise.