DSA-2026-386: Security Update for Dell Secure Connect Gateway Virtual Edition Multiple Vulnerabilities
Summary: Dell Secure Connect Gateway Virtual Edition remediation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system.
This article applies to
This article does not apply to
This article is not tied to any specific product.
Not all product versions are identified in this article.
Impact
Critical
Details
| Third-party Component | CVEs | More Information |
| Apache HTTP Server | CVE-2026-23918, CVE-2026-24072, CVE-2026-28780, CVE-2026-29167, CVE-2026-29168, CVE-2026-29169, CVE-2026-29170, CVE-2026-33006, CVE-2026-33007, CVE-2026-33523, CVE-2026-33857, CVE-2026-34032, CVE-2026-34059, CVE-2026-34355, CVE-2026-34356, CVE-2026-42535, CVE-2026-42536, CVE-2026-43951, CVE-2026-44119, CVE-2026-44185, CVE-2026-44186, CVE-2026-44631, CVE-2026-48913, CVE-2026-49975, CVE-2026-22732, CVE-2025-67735, CVE-2026-33870, CVE-2025-46392 | https://nvd.nist.gov/vuln/search |
| containerd | CVE-2026-33186, CVE-2026-33814, CVE-2026-34986, CVE-2026-39821 | https://nvd.nist.gov/vuln/search |
| Apache Tomcat | CVE-2026-43515, CVE-2026-43512 | https://nvd.nist.gov/vuln/search |
| curl | CVE-2025-14017, CVE-2025-14524, CVE-2025-14819, CVE-2025-15079, CVE-2025-15224, CVE-2026-1965, CVE-2026-3783, CVE-2026-3784, CVE-2026-3805, CVE-2026-4873, CVE-2026-5545, CVE-2026-6253, CVE-2026-6276, CVE-2026-6429, CVE-2026-8286, CVE-2026-8458, CVE-2026-8924, CVE-2026-8927, CVE-2026-9079, CVE-2026-9080, CVE-2026-9545, CVE-2026-9547, CVE-2026-10536, CVE-2026-12064, CVE-2026-3784 | https://nvd.nist.gov/vuln/search |
| Linux Kernel | CVE-2026-64600, CVE-2026-43499, CVE-2021-47621, CVE-2026-46333, CVE-2026-43284, CVE-2026-31431, CVE-2026-23403, CVE-2026-23404, CVE-2026-23405, CVE-2026-23406, CVE-2026-23407, CVE-2026-23408, CVE-2026-23409, CVE-2026-23410, CVE-2026-23411, CVE-2026-43500 | https://nvd.nist.gov/vuln/search |
| Docker | CVE-2025-58181, CVE-2026-39984, CVE-2026-41567, CVE-2026-34040 | https://nvd.nist.gov/vuln/search |
| Spring Framework | CVE-2025-41248, CVE-2025-41232, CVE-2025-41254, CVE-2025-41249, CVE-2026-22735, CVE-2026-22737 | https://nvd.nist.gov/vuln/search |
| dracut | CVE-2026-6893, CVE-2026-15816 | https://nvd.nist.gov/vuln/search |
| Bouncy Castle Java | CVE-2025-8916 | https://nvd.nist.gov/vuln/search |
| GLib | CVE-2026-58010, CVE-2026-58011, CVE-2026-58012, CVE-2026-58013, CVE-2026-58014, CVE-2026-58016 | https://nvd.nist.gov/vuln/search |
| glibc | CVE-2026-4046, CVE-2026-4437, CVE-2026-4438, CVE-2026-5435, CVE-2026-5450, CVE-2026-5928, CVE-2026-6238 | https://nvd.nist.gov/vuln/search |
| gzip | CVE-2026-41991 | https://nvd.nist.gov/vuln/search |
| haveged | CVE-2026-41054, CVE-2026-4105 | https://nvd.nist.gov/vuln/search |
| Kerberos 5 | CVE-2026-11850, CVE-2026-40355, CVE-2026-40356 | https://nvd.nist.gov/vuln/search |
| util-linux | CVE-2025-14104, CVE-2026-3184 | https://nvd.nist.gov/vuln/search |
| libcap | CVE-2026-4878 | https://nvd.nist.gov/vuln/search |
| c-ares | CVE-2016-5180, CVE-2017-1000381, CVE-2020-8277, CVE-2021-3672, CVE-2022-4904, CVE-2023-31124, CVE-2023-31130, CVE-2023-31147, CVE-2023-32067, CVE-2024-25629 | https://nvd.nist.gov/vuln/search |
| Expat | CVE-2026-24515, CVE-2026-25210, CVE-2026-32776, CVE-2026-32777, CVE-2026-32778 | https://nvd.nist.gov/vuln/search |
| GnuTLS | CVE-2014-8564, CVE-2015-6251, CVE-2016-8610, CVE-2017-7869, CVE-2017-10790, CVE-2018-10844, CVE-2018-10845, CVE-2018-10846, CVE-2019-3829, CVE-2019-3836, CVE-2020-13777, CVE-2021-20231, CVE-2021-20232, CVE-2022-2509, CVE-2023-0361, CVE-2023-5981, CVE-2024-0553, CVE-2024-0567, CVE-2024-12243, CVE-2024-28834, CVE-2024-28835, CVE-2025-6395, CVE-2025-9820, CVE-2025-14831, CVE-2025-32988, CVE-2025-32989, CVE-2025-32990, CVE-2026-3833, CVE-2026-5260, CVE-2026-5419, CVE-2026-33845, CVE-2026-33846, CVE-2026-42009, CVE-2026-42010, CVE-2026-42011, CVE-2026-42012, CVE-2026-42013, CVE-2026-42014, CVE-2026-42015 | https://nvd.nist.gov/vuln/search |
| Graphite2 | CVE-2026-50593 | https://nvd.nist.gov/vuln/search |
| Netty | CVE-2026-33871 | https://nvd.nist.gov/vuln/search |
| Nettle | CVE-2015-8803, CVE-2015-8804, CVE-2015-8805, CVE-2016-6489, CVE-2018-16869, CVE-2021-3580, CVE-2021-20305, CVE-2023-36660 | https://nvd.nist.gov/vuln/search |
| LDB | CVE-2015-3223, CVE-2015-5330, CVE-2018-1140, CVE-2019-3824, CVE-2020-10700, CVE-2020-10730, CVE-2020-27840, CVE-2021-3670, CVE-2021-20277, CVE-2022-2031, CVE-2022-32744, CVE-2022-32745, CVE-2022-32746, CVE-2023-0614 | https://nvd.nist.gov/vuln/search |
| XZ Utils | CVE-2026-34743 | https://nvd.nist.gov/vuln/search |
| nghttp2 | CVE-2026-27135 | https://nvd.nist.gov/vuln/search |
| OpenSSL | CVE-2026-7383, CVE-2026-9076, CVE-2026-28387, CVE-2026-28388, CVE-2026-28389, CVE-2026-28390, CVE-2026-31789, CVE-2026-31790, CVE-2026-34180, CVE-2026-34182, CVE-2026-42766, CVE-2026-42767, CVE-2026-42770, CVE-2026-45445, CVE-2026-45446, CVE-2026-45447, CVE-2014-3604 | https://nvd.nist.gov/vuln/search |
| libpng | CVE-2026-33416, CVE-2026-33636, CVE-2026-34757 | https://nvd.nist.gov/vuln/search |
| PostgreSQL | CVE-2026-2003, CVE-2026-2004, CVE-2026-2005, CVE-2026-2006, CVE-2026-2007, CVE-2026-6472, CVE-2026-6473, CVE-2026-6474, CVE-2026-6475, CVE-2026-6476, CVE-2026-6477, CVE-2026-6478, CVE-2026-6479, CVE-2026-6575, CVE-2026-6637, CVE-2026-6638 | https://nvd.nist.gov/vuln/search |
| Python | CVE-2025-13462, CVE-2026-0864, CVE-2026-1299, CVE-2026-1502, CVE-2026-2297, CVE-2026-3276, CVE-2026-3446, CVE-2026-3479, CVE-2026-3644, CVE-2026-4224, CVE-2026-4360, CVE-2026-4519, CVE-2026-4786, CVE-2026-6019, CVE-2026-6100, CVE-2026-7210, CVE-2026-7774, CVE-2026-8328, CVE-2026-11940, CVE-2026-11972, CVE-2026-15308 | https://nvd.nist.gov/vuln/search |
| Shibboleth | CVE-2025-9943 | https://nvd.nist.gov/vuln/search |
| libsolv | CVE-2026-9149, CVE-2026-9150, CVE-2026-48863 | https://nvd.nist.gov/vuln/search |
| SQLite | CVE-2025-7709, CVE-2025-70873, CVE-2026-11822, CVE-2026-11824 | https://nvd.nist.gov/vuln/search |
| libssh | CVE-2026-0964, CVE-2026-0965, CVE-2026-0966, CVE-2026-0967, CVE-2026-0968, CVE-2026-3731, CVE-2026-59843, CVE-2026-59844, CVE-2026-59845, CVE-2026-59846, CVE-2026-59847, CVE-2026-59848, CVE-2026-59850 | https://nvd.nist.gov/vuln/search |
| libssh2 | CVE-2025-15661, CVE-2026-7598, CVE-2026-55199, CVE-2026-58050, CVE-2026-58051, CVE-2026-66032, CVE-2026-66033, CVE-2026-66034, CVE-2026-66035 | https://nvd.nist.gov/vuln/search |
| SSSD | CVE-2017-12173, CVE-2018-10852, CVE-2018-16838, CVE-2019-3811, CVE-2021-3621, CVE-2023-3758, CVE-2025-11561, CVE-2026-14474, CVE-2026-14476 | https://nvd.nist.gov/vuln/search |
| systemd | CVE-2026-29111 | https://nvd.nist.gov/vuln/search |
| libxml2 | CVE-2025-8732, CVE-2025-10911, CVE-2026-0989, CVE-2026-0990, CVE-2026-0992, CVE-2026-1757, CVE-2026-11979 | https://nvd.nist.gov/vuln/search |
| libzip | CVE-2015-2331, CVE-2017-12858, CVE-2017-14107 | https://nvd.nist.gov/vuln/search |
| libzypp | CVE-2026-25707, CVE-2026-44933, CVE-2026-44941, CVE-2026-44942 | https://nvd.nist.gov/vuln/search |
| OpenSSH | CVE-2026-3497, CVE-2026-35385, CVE-2026-35388, CVE-2026-35414, CVE-2026-59995, CVE-2026-59996, CVE-2026-59997, CVE-2026-59998, CVE-2026-59999, CVE-2026-60000, CVE-2026-60001, CVE-2026-60002 | https://nvd.nist.gov/vuln/search |
| Perl | CVE-2026-8376, CVE-2026-12087, CVE-2026-57432 | https://nvd.nist.gov/vuln/search |
| RPM | CVE-2026-44605 | https://nvd.nist.gov/vuln/search |
| rsync | CVE-2025-10158, CVE-2026-29518, CVE-2026-41035, CVE-2026-43617, CVE-2026-43618, CVE-2026-43619, CVE-2026-43620, CVE-2026-45232 | https://nvd.nist.gov/vuln/search |
| rsyslog | CVE-2026-61548 | https://nvd.nist.gov/vuln/search |
| runc | CVE-2026-41579 | https://nvd.nist.gov/vuln/search |
| shim | CVE-2024-2312 | https://nvd.nist.gov/vuln/search |
| sudo | CVE-2026-35535 | https://nvd.nist.gov/vuln/search |
| tar | CVE-2025-45582, CVE-2026-5704 | https://nvd.nist.gov/vuln/search |
| Vim | CVE-2026-26269, CVE-2026-28417, CVE-2026-33412, CVE-2026-34714, CVE-2026-34982, CVE-2026-39881, CVE-2026-42307, CVE-2026-43961, CVE-2026-44656, CVE-2026-45130, CVE-2026-46483, CVE-2026-59856, CVE-2026-59857, CVE-2026-59858 | https://nvd.nist.gov/vuln/search |
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
| CVE-2026-80247 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a Missing Authentication for Critical Function vulnerability. An attacker with local access to the appliance could potentially exploit this vulnerability, leading to unauthorized access to sensitive information, modification of protected resources, and execution of privileged operations within the appliance security context, potentially resulting in compromise of confidentiality, integrity, and availability. | 8.4 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| CVE-2026-80273 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An attacker with local access to the appliance could potentially exploit this vulnerability, leading to arbitrary command execution and privilege escalation, resulting in complete compromise of confidentiality, integrity, and availability of the appliance. | 8.4 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| CVE-2026-80283 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a Missing Authentication for Critical Function vulnerability. An attacker with local access could potentially exploit this vulnerability, leading to unauthorized disclosure of sensitive information, unauthorized modification of system resources, and execution of privileged actions that could lead to compromise of the appliance. | 8.4 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| CVE-2026-80287 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a Missing Authentication for Critical Function vulnerability. An attacker with local access could potentially exploit this vulnerability, leading to unauthorized access to system resources, disclosure of sensitive information, modification of protected configurations, and execution of privileged operations. | 8.4 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| CVE-2026-80291 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a Missing Authentication for Critical Function vulnerability. A local attacker could potentially exploit this vulnerability, leading to unauthorized access to sensitive data, modification of critical resources, and disruption of appliance functionality. | 8.4 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| CVE-2026-80361 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a Missing Authentication for Critical Function vulnerability. An attacker with local access to the appliance could potentially exploit this vulnerability, leading to unauthorized access to sensitive information, unauthorized modification of application data, and execution of actions with elevated privileges within the appliance environment. | 8.4 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| CVE-2026-80367 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains an Out-of-bounds Write vulnerability. A local attacker could potentially exploit this vulnerability, leading to application instability, denial of service, disclosure of sensitive information, arbitrary memory modification, and potentially execution of attacker-controlled code within the affected process. | 8.4 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| CVE-2026-80267 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a Use of Hard-coded Credentials vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to unauthorized access. | 7.8 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| CVE-2026-80271 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a Use of Hard-coded Cryptographic Key vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to remote execution. | 7.8 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| CVE-2026-80284 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains an Improper Authentication vulnerability. An attacker with local access could potentially exploit this vulnerability, leading to exposure of sensitive data and unauthorized modification of system operations. | 7.8 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
| CVE-2026-80285 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains an Execution with Unnecessary Privileges vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges. | 7.8 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| CVE-2026-80363 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a Use of Hard-coded Credentials vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to unauthorized access. | 7.8 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| CVE-2026-80364 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a Download of Code Without Integrity Check vulnerability. A low privileged local attacker could potentially exploit this vulnerability, leading to full compromise of confidentiality, integrity, and availability. | 7.8 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| CVE-2026-80365 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a Use of Externally-Controlled Format String vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to remote execution. | 7.8 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| CVE-2026-80369 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains an Uncontrolled Search Path Element vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to remote execution. | 7.8 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| CVE-2026-80286 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains an External Control of File Name or Path vulnerability. A low privileged local attacker could potentially exploit this vulnerability, leading to unauthorized file access, modification, potentially compromising confidentiality and integrity. | 7.6 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L |
| CVE-2026-80269 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains an Insecure Temporary File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to filesystem access for attacker. | 7.3 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L |
| CVE-2026-80296 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a Path Traversal vulnerability. A low privileged local attacker could potentially exploit this vulnerability, leading to unauthorized file access, modification, or disruption of system operations. | 7.3 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H |
| CVE-2026-80297 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a Path Traversal vulnerability. A low privileged local attacker could potentially exploit this vulnerability, leading to unauthorized file access, modification, or disruption of system operations. | 7.3 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H |
| CVE-2026-80288 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains an Improper Input Validation vulnerability. An attacker with local access could potentially exploit this vulnerability, leading to unauthorized access to sensitive information and privileged functionality. | 6.8 | CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N |
| CVE-2026-80290 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a Race Condition vulnerability. A low privileged local attacker could potentially exploit this vulnerability, leading to unauthorized modification of data or service disruption. | 6.6 | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H |
| CVE-2026-80260 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to remote execution. | 6.3 | CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H |
| CVE-2026-80366 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains an Out-of-bounds Read vulnerability. An attacker with local access could potentially exploit this vulnerability, leading to sensitive information exposure and application instability. | 6.2 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H |
| CVE-2026-80251 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains an Exposure of Sensitive Information vulnerability. An attacker with local access to the appliance could potentially exploit this vulnerability, leading to confidentiality impact. | 5.5 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
| CVE-2026-80259 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains an Exposure of File Descriptor to Unintended Control Sphere ('File Descriptor Leak') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information exposure. | 5.5 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
| CVE-2026-80261 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains an Argument Injection vulnerability. A low privileged local attacker could potentially exploit this vulnerability, leading to disclosure of sensitive information and limited integrity impact. | 5.5 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N |
| CVE-2026-80293 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains an Argument Injection vulnerability. A low privileged local attacker could potentially exploit this vulnerability, leading to disclosure of sensitive information and limited integrity impact. | 5.5 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N |
| CVE-2026-80294 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to command execution. | 5.5 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
| CVE-2026-80263 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a Heap-based Buffer Overflow vulnerability. A low privileged local attacker could potentially exploit this vulnerability, leading to application crashes, denial of service, disclosure of sensitive information, modification of application data, and potentially arbitrary code execution within the affected process. | 5.3 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
| CVE-2026-80249 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a Server-Side Request Forgery (SSRF) vulnerability. A local attacker with access to the appliance could potentially exploit this vulnerability, leading to information disclosure or unauthorized interaction with trusted services. | 4.6 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
| CVE-2026-80265 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a Server-Side Request Forgery (SSRF) vulnerability. An attacker with local access could potentially exploit this vulnerability, leading to information exposure and affecting application integrity. | 4.6 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
| CVE-2026-80270 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains an XML Injection vulnerability. An attacker with local access could potentially exploit this vulnerability, leading to unauthorized data access or manipulation. | 4.6 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
| CVE-2026-80272 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a Missing Authorization vulnerability. An attacker with local access could potentially exploit this vulnerability, leading to unauthorized actions and information exposure. | 4.6 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
| CVE-2026-80360 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains an Incorrect Authorization vulnerability. An attacker with local access could potentially exploit this vulnerability, leading to actions beyond intended permissions. | 4.6 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
| CVE-2026-80362 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains an Uninitialized Variable vulnerability. A local attacker could potentially exploit this vulnerability, leading to information exposure or denial of service. | 4.4 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L |
| CVE-2026-80262 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a CRLF Injection vulnerability. A low privileged local attacker could potentially exploit this vulnerability, leading to altering application-generated content and affecting system integrity. | 4.2 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
| CVE-2026-80295 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a TOCTOU Race Condition vulnerability. A low privileged local attacker could potentially exploit this vulnerability, leading to limited integrity impact and service instability. | 3.8 | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L |
| CVE-2026-80252 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a NULL Pointer Dereference vulnerability. An attacker with local access could potentially exploit this vulnerability, leading to denial of service. | 3.3 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
| CVE-2026-80368 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains an Improper Output Neutralization for Logs vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to server-side request forgery. | 3.1 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
| CVE-2026-80250 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains an Invocation of Process Using Visible Sensitive Information vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information exposure. | 2.5 | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N |
| CVE-2026-80264 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a Free of Memory not on the Heap vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to denial of service. | 2.5 | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L |
| CVE-2026-80266 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains an Improper Removal of Sensitive Information Before Storage or Transfer vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information exposure. | 2.5 | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N |
| CVE-2026-80292 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to session theft. | 2.5 | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L |
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
| CVE-2026-80247 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a Missing Authentication for Critical Function vulnerability. An attacker with local access to the appliance could potentially exploit this vulnerability, leading to unauthorized access to sensitive information, modification of protected resources, and execution of privileged operations within the appliance security context, potentially resulting in compromise of confidentiality, integrity, and availability. | 8.4 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| CVE-2026-80273 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An attacker with local access to the appliance could potentially exploit this vulnerability, leading to arbitrary command execution and privilege escalation, resulting in complete compromise of confidentiality, integrity, and availability of the appliance. | 8.4 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| CVE-2026-80283 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a Missing Authentication for Critical Function vulnerability. An attacker with local access could potentially exploit this vulnerability, leading to unauthorized disclosure of sensitive information, unauthorized modification of system resources, and execution of privileged actions that could lead to compromise of the appliance. | 8.4 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| CVE-2026-80287 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a Missing Authentication for Critical Function vulnerability. An attacker with local access could potentially exploit this vulnerability, leading to unauthorized access to system resources, disclosure of sensitive information, modification of protected configurations, and execution of privileged operations. | 8.4 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| CVE-2026-80291 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a Missing Authentication for Critical Function vulnerability. A local attacker could potentially exploit this vulnerability, leading to unauthorized access to sensitive data, modification of critical resources, and disruption of appliance functionality. | 8.4 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| CVE-2026-80361 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a Missing Authentication for Critical Function vulnerability. An attacker with local access to the appliance could potentially exploit this vulnerability, leading to unauthorized access to sensitive information, unauthorized modification of application data, and execution of actions with elevated privileges within the appliance environment. | 8.4 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| CVE-2026-80367 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains an Out-of-bounds Write vulnerability. A local attacker could potentially exploit this vulnerability, leading to application instability, denial of service, disclosure of sensitive information, arbitrary memory modification, and potentially execution of attacker-controlled code within the affected process. | 8.4 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| CVE-2026-80267 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a Use of Hard-coded Credentials vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to unauthorized access. | 7.8 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| CVE-2026-80271 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a Use of Hard-coded Cryptographic Key vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to remote execution. | 7.8 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| CVE-2026-80284 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains an Improper Authentication vulnerability. An attacker with local access could potentially exploit this vulnerability, leading to exposure of sensitive data and unauthorized modification of system operations. | 7.8 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
| CVE-2026-80285 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains an Execution with Unnecessary Privileges vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to elevation of privileges. | 7.8 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| CVE-2026-80363 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a Use of Hard-coded Credentials vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to unauthorized access. | 7.8 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| CVE-2026-80364 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a Download of Code Without Integrity Check vulnerability. A low privileged local attacker could potentially exploit this vulnerability, leading to full compromise of confidentiality, integrity, and availability. | 7.8 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| CVE-2026-80365 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a Use of Externally-Controlled Format String vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to remote execution. | 7.8 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| CVE-2026-80369 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains an Uncontrolled Search Path Element vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to remote execution. | 7.8 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| CVE-2026-80286 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains an External Control of File Name or Path vulnerability. A low privileged local attacker could potentially exploit this vulnerability, leading to unauthorized file access, modification, potentially compromising confidentiality and integrity. | 7.6 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L |
| CVE-2026-80269 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains an Insecure Temporary File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to filesystem access for attacker. | 7.3 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L |
| CVE-2026-80296 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a Path Traversal vulnerability. A low privileged local attacker could potentially exploit this vulnerability, leading to unauthorized file access, modification, or disruption of system operations. | 7.3 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H |
| CVE-2026-80297 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a Path Traversal vulnerability. A low privileged local attacker could potentially exploit this vulnerability, leading to unauthorized file access, modification, or disruption of system operations. | 7.3 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H |
| CVE-2026-80288 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains an Improper Input Validation vulnerability. An attacker with local access could potentially exploit this vulnerability, leading to unauthorized access to sensitive information and privileged functionality. | 6.8 | CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N |
| CVE-2026-80290 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a Race Condition vulnerability. A low privileged local attacker could potentially exploit this vulnerability, leading to unauthorized modification of data or service disruption. | 6.6 | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H |
| CVE-2026-80260 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to remote execution. | 6.3 | CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H |
| CVE-2026-80366 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains an Out-of-bounds Read vulnerability. An attacker with local access could potentially exploit this vulnerability, leading to sensitive information exposure and application instability. | 6.2 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H |
| CVE-2026-80251 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains an Exposure of Sensitive Information vulnerability. An attacker with local access to the appliance could potentially exploit this vulnerability, leading to confidentiality impact. | 5.5 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
| CVE-2026-80259 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains an Exposure of File Descriptor to Unintended Control Sphere ('File Descriptor Leak') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information exposure. | 5.5 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
| CVE-2026-80261 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains an Argument Injection vulnerability. A low privileged local attacker could potentially exploit this vulnerability, leading to disclosure of sensitive information and limited integrity impact. | 5.5 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N |
| CVE-2026-80293 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains an Argument Injection vulnerability. A low privileged local attacker could potentially exploit this vulnerability, leading to disclosure of sensitive information and limited integrity impact. | 5.5 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N |
| CVE-2026-80294 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to command execution. | 5.5 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
| CVE-2026-80263 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a Heap-based Buffer Overflow vulnerability. A low privileged local attacker could potentially exploit this vulnerability, leading to application crashes, denial of service, disclosure of sensitive information, modification of application data, and potentially arbitrary code execution within the affected process. | 5.3 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
| CVE-2026-80249 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a Server-Side Request Forgery (SSRF) vulnerability. A local attacker with access to the appliance could potentially exploit this vulnerability, leading to information disclosure or unauthorized interaction with trusted services. | 4.6 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
| CVE-2026-80265 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a Server-Side Request Forgery (SSRF) vulnerability. An attacker with local access could potentially exploit this vulnerability, leading to information exposure and affecting application integrity. | 4.6 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
| CVE-2026-80270 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains an XML Injection vulnerability. An attacker with local access could potentially exploit this vulnerability, leading to unauthorized data access or manipulation. | 4.6 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
| CVE-2026-80272 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a Missing Authorization vulnerability. An attacker with local access could potentially exploit this vulnerability, leading to unauthorized actions and information exposure. | 4.6 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
| CVE-2026-80360 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains an Incorrect Authorization vulnerability. An attacker with local access could potentially exploit this vulnerability, leading to actions beyond intended permissions. | 4.6 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
| CVE-2026-80362 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains an Uninitialized Variable vulnerability. A local attacker could potentially exploit this vulnerability, leading to information exposure or denial of service. | 4.4 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L |
| CVE-2026-80262 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a CRLF Injection vulnerability. A low privileged local attacker could potentially exploit this vulnerability, leading to altering application-generated content and affecting system integrity. | 4.2 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
| CVE-2026-80295 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a TOCTOU Race Condition vulnerability. A low privileged local attacker could potentially exploit this vulnerability, leading to limited integrity impact and service instability. | 3.8 | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L |
| CVE-2026-80252 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a NULL Pointer Dereference vulnerability. An attacker with local access could potentially exploit this vulnerability, leading to denial of service. | 3.3 | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
| CVE-2026-80368 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains an Improper Output Neutralization for Logs vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to server-side request forgery. | 3.1 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
| CVE-2026-80250 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains an Invocation of Process Using Visible Sensitive Information vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information exposure. | 2.5 | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N |
| CVE-2026-80264 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a Free of Memory not on the Heap vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to denial of service. | 2.5 | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L |
| CVE-2026-80266 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains an Improper Removal of Sensitive Information Before Storage or Transfer vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information exposure. | 2.5 | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N |
| CVE-2026-80292 | Dell Secure Connect Gateway (SCG) Virtual Edition, versions prior to 5.36.00.16, contains a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to session theft. | 2.5 | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L |
Affected Products & Remediation
| Product | Affected Versions | Remediated Versions | Link |
| Dell Secure Connect Gateway Virtual Edition | Versions prior to 5.36.00.16 | Version 5.36.00.16 or later | Dell Secure Connect Gateway Virtual Edition |
| Product | Affected Versions | Remediated Versions | Link |
| Dell Secure Connect Gateway Virtual Edition | Versions prior to 5.36.00.16 | Version 5.36.00.16 or later | Dell Secure Connect Gateway Virtual Edition |
The Affected Products and Remediation table above may not be a comprehensive list of all affected supported versions and may be updated as more information becomes available.
Workarounds & Mitigations
None
Revision History
| Revision | Date | Description |
| 1.0 | 2026-08-31 | Initial Release |
| 2.0 | 2026-09-01 | Formatting changes without any updates to data |
Related Information
Legal Disclaimer
Affected Products
Secure Connect Gateway, Secure Connect Gateway - Virtual EditionArticle Properties
Article Number: 000503504
Article Type: Dell Security Advisory
Last Modified: 01 Sep 2026
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.