Dell patches Secure Connect Gateway flaws - but is CVE-2026-79941 really 'critical'?
A newly listed Dell bug is tagged critical severity despite carrying a CVSS score that normally means 'medium' - here's what's actually confirmed.
Dell has pushed out a security update for its Secure Connect Gateway (SCG) software, fixing a batch of vulnerabilities disclosed under advisory DSA-2026-382. One of them, CVE-2026-79941, is being flagged in early reporting as “critical” - but the CVSS score attached to it, 5.3, is the kind of number that normally gets filed under “medium”. That mismatch is the first thing worth checking before anyone panics.
What’s actually confirmed
Dell’s advisory covers Secure Connect Gateway 5.0, both the Appliance and Application builds, running versions older than 5.36.00.16 (Appliance) or 5.36.00.00 (Application). SCG is enterprise kit - it’s the remote-monitoring and support-connectivity tool Dell uses to link customer hardware back to Dell for diagnostics and updates. It is not consumer software sitting on someone’s home PC.
The advisory bundles several distinct flaws together, and some of them are genuinely nasty. CVE-2026-61410 is described as a missing-authorisation bug that lets an unauthenticated attacker send a crafted request and get remote code execution, no login required. CVE-2026-80172 is worse again: a token-verification failure that means an attacker who intercepts a single request can replay it indefinitely to mint fresh admin access and refresh tokens, because there’s no nonce or time limit on the requests. Both of those carry a CVSS of 9.8 - properly critical by any reasonable definition.
CVE-2026-79941 itself is described in NVD’s summary as an “Improper Neutralization of Special Elements used in a Command” issue - in plain English, a command injection flaw, the class of bug where unsanitised input lets an attacker run their own system commands. The full text of Dell’s description for this specific CVE was cut off in the material available, so the precise attack path - whether it needs authentication, what privileges it needs, how it’s actually triggered - isn’t confirmed here. What is confirmed is the version ranges affected and that a fix exists.
So who’s actually at risk
If you’re not running Dell Secure Connect Gateway, this doesn’t touch you. If your organisation is running it - likely IT teams managing Dell enterprise hardware fleets - the sensible move is to check which of the bundled CVEs actually apply to your deployment, because the advisory groups several bugs of very different severity under one update. Nothing in Dell’s advisory or the NVD listing states that any of these flaws, including CVE-2026-79941, are being actively exploited. That’s a meaningful distinction: a newly disclosed bug with a patch already available is a very different situation to one being used against real systems today.
The “critical” tag being applied to CVE-2026-79941 in some early write-ups looks like it may be borrowing the overall advisory’s severity rating - Dell classifies the whole DSA-2026-382 update as “Critical” - rather than reflecting this specific CVE’s own 5.3 score. Worth remembering that Dell’s advisories often bundle low, medium and critical bugs under one umbrella rating for the update as a whole.
What to do about it
If you administer Dell SCG, update to Appliance 5.36.00.16