PatchSiren cyber security CVE debrief
CVE-2026-61410 Dell CVE debrief
Dell Secure Connect Gateway (SCG) 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00 contain a Missing Authorization vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to remote execution. This vulnerability affects Dell SCG 5.0 Appliance and Application deployments. Defenders should assess exposure and prioritize upgrading to the latest versions. The vulnerability allows unauthenticated remote execution by sending a specially crafted request to the application, bypassing intended restrictions on code execution.
- Vendor
- Dell
- Product
- Secure Connect Gateway 5.0 - Application
- CVSS
- CRITICAL 9.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-07
- Original CVE updated
- 2026-09-07
- Advisory published
- 2026-09-07
- Advisory updated
- 2026-09-07
Who should care
Defenders responsible for Dell SCG 5.0 Appliance and Application deployments should assess exposure and prioritize upgrading to the latest versions. This includes operators, platform administrators, vulnerability management teams, and security teams who need to review and implement necessary mitigations.
Why it matters
CVE-2026-61410 is a critical vulnerability in Dell SCG 5.0 Appliance and Application that allows unauthenticated remote execution. Defenders should prioritize upgrading to the latest versions and verify remote access restrictions.
- Remote execution could lead to unauthorized access and control of the target system.
- Successful exploitation could result in lateral movement within the network.
- Defenders should verify remote access restrictions and monitor for suspicious activity.
- Remediation priority is high due to the critical CVSS score of 9.4.
Technical summary
The vulnerability exists in Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to remote execution, by sending a specially crafted request to the application, bypassing intended restrictions on code execution. This vulnerability is considered critical because it allows an attacker to execute commands remotely on a target system. Defenders should prioritize upgrading to the latest versions and verify remote access restrictions.
Defensive priority
Upgrade to the latest version at the earliest opportunity.
Recommended defensive actions
- Upgrade Dell SCG 5.0 Appliance to version 5.36.00.16 or later
- Upgrade Dell SCG 5.0 Application to version 5.36.00.00 or later
- Verify remote access restrictions and monitor for suspicious activity
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, but do not offer additional information on exploitation or impact. The vulnerability exists in Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00. Dell recommends customers to upgrade at the earliest opportunity. There is no evidence of public exploitation or widespread impact.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-61410 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-61410
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-61410 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-61410
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.