Dell patched multiple critical flaws in its Secure Connect Gateway on August 31, 2026. The most severe Dell Secure Connect Gateway vulnerability, CVE-2026-80172, scores a 9.8 CVSS. It lets an unauthenticated attacker forge admin tokens and gain unauthorized access. Two other critical bugs enable remote code execution and root-level takeover.
- Product: Dell Secure Connect Gateway 5.0 - Application
- Vulnerabilities: 2 flaws (CVE-2026-61410, CVE-2026-80238)
- Highest severity: 9.4 (Critical · CVSSv3)
- Status: No confirmed exploitation yet; patches available
- Action: Update to 5.36.00.00 or later, 5.36.00.16 or later now
| CVE | CVSS (CVSSv3) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-61410 | 9.4 | CWE-862 | 5.36.00.00 or later, 5.36.00.16 or later | Not exploited |
| CVE-2026-80238 | 9.3 | CWE-250 | 5.36.00.00 or later, 5.36.00.16 or later | Not exploited |
Why this matters
Secure Connect Gateway (SCG) connects Dell hardware to Dell support services. So it sits deep inside data-center and enterprise networks. A takeover here could expose managed infrastructure. The advisory, DSA-2026-382, lists roughly 100 fixes in total. This report focuses on the three rated critical.
How the attacks work
The top flaw is an authentication weakness. Per Dell, “an unauthenticated attacker can repeatedly reuse a captured request to generate ADMIN access and refresh tokens.” Because there is “no nonce validation or time limit on requests, the attack can be performed indefinitely.” That gives an attacker durable unauthorized access.
The second bug, CVE-2026-61410, is a missing-authorization flaw scored 9.4. It allows remote command execution through a crafted request that bypasses code-execution restrictions. The third, CVE-2026-80238, scores 9.3. It lets a low-privileged operator abuse an exposed Docker socket to reach root and escape the container.
Affected versions
The flaws affect Dell SCG 5.0 Appliance builds before 5.36.00.16. They also affect SCG 5.0 Application builds before 5.36.00.00. Dell reports no active exploitation and no public proof-of-concept at this time.
Patch and mitigation steps
Update now, since Dell lists no workarounds. Move the Appliance to 5.36.00.16 or later, and the Application to 5.36.00.00 or later. Review the full Dell security advisory for the complete CVE list. Restrict network access to the SCG console until every unit is patched.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!