PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-61410 Dell CVE debrief

Dell Secure Connect Gateway (SCG) 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00 contain a Missing Authorization vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to remote execution. This vulnerability affects Dell SCG 5.0 Appliance and Application deployments. Defenders should assess exposure and prioritize upgrading to the latest versions. The vulnerability allows unauthenticated remote execution by sending a specially crafted request to the application, bypassing intended restrictions on code execution.

Vendor
Dell
Product
Secure Connect Gateway 5.0 - Application
CVSS
CRITICAL 9.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-07
Original CVE updated
2026-09-07
Advisory published
2026-09-07
Advisory updated
2026-09-07

Who should care

Defenders responsible for Dell SCG 5.0 Appliance and Application deployments should assess exposure and prioritize upgrading to the latest versions. This includes operators, platform administrators, vulnerability management teams, and security teams who need to review and implement necessary mitigations.

Why it matters

CVE-2026-61410 is a critical vulnerability in Dell SCG 5.0 Appliance and Application that allows unauthenticated remote execution. Defenders should prioritize upgrading to the latest versions and verify remote access restrictions.

  • Remote execution could lead to unauthorized access and control of the target system.
  • Successful exploitation could result in lateral movement within the network.
  • Defenders should verify remote access restrictions and monitor for suspicious activity.
  • Remediation priority is high due to the critical CVSS score of 9.4.

Technical summary

The vulnerability exists in Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to remote execution, by sending a specially crafted request to the application, bypassing intended restrictions on code execution. This vulnerability is considered critical because it allows an attacker to execute commands remotely on a target system. Defenders should prioritize upgrading to the latest versions and verify remote access restrictions.

Defensive priority

Upgrade to the latest version at the earliest opportunity.

Recommended defensive actions

  • Upgrade Dell SCG 5.0 Appliance to version 5.36.00.16 or later
  • Upgrade Dell SCG 5.0 Application to version 5.36.00.00 or later
  • Verify remote access restrictions and monitor for suspicious activity
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, but do not offer additional information on exploitation or impact. The vulnerability exists in Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00. Dell recommends customers to upgrade at the earliest opportunity. There is no evidence of public exploitation or widespread impact.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-61410 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-61410

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-61410 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-61410

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-connect-gateway-virtual-edition-multiple-vulnerabilities

    [email protected]

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.