vciy

Dell Secure Connect Gateway: 70 records in one advisory

70 records announced together, published between 2026-09-07 and 2026-09-09, every one of them citing the same advisory.

The advisory

Every record in this batch cites https://www.dell.com/support/kbdoc/en-in/000503426/dsa-2026-382-security-update-for-dell-secure-…. That is the CNA's own reference, held in the index, and it is why these records are on one page.

What the records offer

All 70 records publish a fixed version.

No record in this batch is listed by CISA in held sources.

22 of 70 records name something of its own. For the other 48, held sources say the same thing about each.

Most commonly mapped weakness across the batch: CWE-295: Improper Certificate Validation.

What this page does not cover

This batch is 70 of the 73 records that cite the same advisory. The other 3 are different findings announced alongside it.

None of those 3 is grouped with any other. Each one has its own record page and nothing else.

The batch is what one advisory announced. It is not every record sharing this weakness, this product or this mechanism, and nothing here is scoped to any estate.

What this batch was researched, not held

Dell's Secure Connect Gateway advisory lists 105 flaws in its own code across 43 weakness types

DSA-2026-382 covers Dell Secure Connect Gateway, the appliance that carries support telemetry out of customer data centres. Dell's Proprietary Code table on that advisory lists 105 identifiers, and a separate third-party row lists one more, CVE-2025-26333 in the BSAFE Crypto-J library. Dell says the affected builds are the 5.0 appliance before 5.36.00.16 and the 5.0 application before 5.36.00.00. The public records tell you more about the shape of the work than the table does. Reading the 104 of those 105 that have a published record, each one names a weakness class in Dell's own wording, and there are 43 distinct classes among them. The largest is improper certificate validation with 20, then command injection into the operating system with 10, then hard-coded credentials with 6 and hard-coded cryptographic keys with 6. Twenty-three of the 43 classes appear exactly once. That spread, from cleartext password storage to a race condition to an open server-side request forgery, is what a review of a whole product looks like rather than one researcher's find. The three highest-scored entries are described by CyberSecurityNews as a token-forgery flaw where captured requests can be replayed to mint administrator tokens because there is no nonce or time limit, a missing authorisation check that allows remote command execution, and an exposed Docker socket that lets a low-privileged operator with shell access reach root.

These 105 were announced in one table and Dell's own remedy line names one pair of builds for all of them, which is Dell's statement about Dell's product. It is not a statement that the flaws are related. The 20 certificate validation entries are 20 separate rows, not one flaw counted twenty times, and the record you are reading shares a table and a remedy with the rest and nothing more.

2026-09-07The first 36 public records referencing this advisory are published.
2026-09-09A further 68 are published, bringing the total to 104.

Dell does not name a component, a file, an endpoint or a parameter for any entry, so the weakness class is all you get. One of the 105, CVE-2026-61408, still had no published record on 18 September 2026, so for that one there is no public description at all. The advisory's acknowledgements and revision history do not render for automated readers, so who found these and when Dell first posted the advisory cannot be established from here.

Written from dell.com, cybersecuritynews.com, services.nvd.nist.gov. Reviewed for whether every claim traces to one of them, by two independent graders, citation support 4.44 of 5, uniqueness 4 of 5. Stated at high confidence. Nothing in this box is a value the index holds, and none of it opens a receipt.

Listed for shared announcement, not shared vulnerability. Each record here is its own finding with its own page, and fixing one does not address another.

CVE-2026-61410authorization because it allowsCWE-862: Missing Authorization
CVE-2026-78481no title heldCWE-321: Use of Hard-coded Cryptographic Key
CVE-2026-78482no title heldCWE-89: Improper Neutralization of Special…
CVE-2026-78483no title heldCWE-295: Improper Certificate Validation
CVE-2026-78484no title heldCWE-77: Improper Neutralization of Special…
CVE-2026-78485limitation pathname restrictedCWE-22: Improper Limitation of a Pathname to a…
CVE-2026-78486no title heldCWE-321: Use of Hard-coded Cryptographic Key
CVE-2026-78489no title heldCWE-295: Improper Certificate Validation
CVE-2026-78490restriction excessive attempts client-sideCWE-307: Improper Restriction of Excessive…
CVE-2026-78491no title heldCWE-295: Improper Certificate Validation
CVE-2026-78492no title heldCWE-295: Improper Certificate Validation
CVE-2026-78493no title heldCWE-77: Improper Neutralization of Special…
CVE-2026-78494no title heldCWE-295: Improper Certificate Validation
CVE-2026-79635no title heldCWE-918: Server-Side Request Forgery (SSRF)
CVE-2026-79636host mismatchCWE-297: Improper Validation of Certificate…
CVE-2026-79637no title heldCWE-295: Improper Certificate Validation
CVE-2026-79638no title heldCWE-693: Protection Mechanism Failure
CVE-2026-79640no title heldCWE-89: Improper Neutralization of Special…
CVE-2026-79641no title heldCWE-78: Improper Neutralization of Special…
CVE-2026-79689no title heldCWE-78: Improper Neutralization of Special…
CVE-2026-79690no title heldCWE-295: Improper Certificate Validation
CVE-2026-79692nameCWE-73: External Control of File Name or Path
CVE-2026-79693no title heldCWE-272: Least Privilege Violation
CVE-2026-79694debuggingCWE-215: Insertion of Sensitive Information…
CVE-2026-79695handling highly compressed amplificationCWE-409: Improper Handling of Highly Compressed…
CVE-2026-79727no title heldCWE-1258: Exposure of Sensitive System…
CVE-2026-79728no title heldCWE-23: Relative Path Traversal
CVE-2026-79729no title heldCWE-295: Improper Certificate Validation
CVE-2026-79730no title heldCWE-367: Time-of-check Time-of-use (TOCTOU)…
CVE-2026-79731no title heldCWE-798: Use of Hard-coded Credentials
CVE-2026-79735disclosureCWE-321: Use of Hard-coded Cryptographic Key
CVE-2026-79736no title heldCWE-295: Improper Certificate Validation
CVE-2026-79738no title heldCWE-798: Use of Hard-coded Credentials
CVE-2026-79740no title heldCWE-798: Use of Hard-coded Credentials
CVE-2026-79741no title heldCWE-77: Improper Neutralization of Special…
CVE-2026-79941no title heldCWE-77: Improper Neutralization of Special…
CVE-2026-79942unnecessaryCWE-250: Execution with Unnecessary Privileges
CVE-2026-79944no title heldCWE-272: Least Privilege Violation
CVE-2026-79945no title heldCWE-77: Improper Neutralization of Special…
CVE-2026-79946no title heldCWE-87: Improper Neutralization of Alternate…
CVE-2026-79947no title heldCWE-89: Improper Neutralization of Special…
CVE-2026-79950no title heldCWE-798: Use of Hard-coded Credentials
CVE-2026-79952encoding escaping outputCWE-116: Improper Encoding or Escaping of Output
CVE-2026-79961no title heldCWE-306: Missing Authentication for Critical…
CVE-2026-79962no title heldCWE-567: Unsynchronized Access to Shared Data…
CVE-2026-79963download without integrity checkCWE-494: Download of Code Without Integrity…
CVE-2026-79964escape meta sequencesCWE-116: Improper Encoding or Escaping of Output
CVE-2026-79965stateCWE-625: Permissive Regular Expression
CVE-2026-79966CWE-532: Insertion of Sensitive Information into Log File
CVE-2026-79967no title heldCWE-295: Improper Certificate Validation
CVE-2026-79968no title heldCWE-367: Time-of-check Time-of-use (TOCTOU)…
CVE-2026-79969no title heldCWE-567: Unsynchronized Access to Shared Data…
CVE-2026-79970signatureCWE-347: Improper Verification of Cryptographic…
CVE-2026-79971sanitization custom charactersCWE-1236: Improper Neutralization of Formula…
CVE-2026-79972no title heldCWE-89: Improper Neutralization of Special…
CVE-2026-79973unsynchronized multithreaded contextCWE-567: Unsynchronized Access to Shared Data…
CVE-2026-79974no title heldCWE-287: Improper Authentication
CVE-2026-80055ldap query ldapCWE-90: Improper Neutralization of Special…
CVE-2026-80122no title heldCWE-295: Improper Certificate Validation
CVE-2026-80123no title heldCWE-918: Server-Side Request Forgery (SSRF)
CVE-2026-80124no title heldCWE-532: Insertion of Sensitive Information…
CVE-2026-80133no title heldCWE-23: Relative Path Traversal
CVE-2026-80134no title heldCWE-798: Use of Hard-coded Credentials
CVE-2026-80169no title heldCWE-532: Insertion of Sensitive Information…
CVE-2026-80171entropy prngCWE-331: Insufficient Entropy
CVE-2026-80172authenticity as can repeatedlyCWE-345: Insufficient Verification of Data…
CVE-2026-80174session expiration session theftCWE-613: Insufficient Session Expiration
CVE-2026-80175externally-accessibleCWE-538: Insertion of Sensitive Information…
CVE-2026-80177no title heldCWE-89: Improper Neutralization of Special…
CVE-2026-80239physicalCWE-1258: Exposure of Sensitive System…

70 records, read from the index as it stood on 2026-09-20. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.