ZeroHour

Vulnerabilities

63 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-78491
Improper Certificate Validation in Dell Secure Connect Gateway 5.0

Dell Secure Connect Gateway (SCG) 5.0 Appliance and Application contain an improper certificate validation flaw (CWE-295), meaning the gateway does not adequately validate TLS certificates when handling remote connections. An unauthenticated attacker with remote access could exploit this, for example by presenting a spoofed or rogue certificate, to gain unauthorized access; the CVSS 3.1 vector scores the impact as low on integrity and high on availability, with no direct confidentiality impact. Affected deployments are SCG 5.0 Appliance versions prior to 5.36.00.16 and SCG 5.0 Application versions prior to 5.36.00.00, which are separately versioned products. There are no known reports of exploitation in the wild, no public proof-of-concept, and the issue is not in the CISA KEV catalog.

Do: Upgrade SCG 5.0 Appliance to 5.36.00.16 or later and SCG 5.0 Application to 5.36.00.00 or later, following Dell's security advisory. Until patched, restrict the gateway's management interfaces to trusted networks only and review logs for unexpected remote connections. Inventory both the appliance and application variants separately, since they follow different version tracks.

8.2
group max
<1%
  • Dell Secure Connect Gateway 5.0 Appliance all versions prior to 5.36.00.16
  • Dell Secure Connect Gateway 5.0 Application all versions prior to 5.36.00.00
largelikely on the order of tens of thousands of enterprise deployments