# Dell Secure Connect Gateway Flaws Enable Code Execution

Published: 2026-09-07 · Severity: routine · Sectors: technology, government-national
Canonical: https://vorant.io/reports/2728fa59-97e0-538a-be6d-a55267695c1d/dell-secure-connect-gateway-flaws-enable-code-execution

> Multiple vulnerabilities in Dell Secure Connect Gateway could let attackers execute arbitrary code with the logged-on user's privileges.

MS-ISAC issued an advisory detailing multiple vulnerabilities in Dell Secure Connect Gateway, an enterprise monitoring and connection tool for Dell infrastructure. The most severe of these flaws could allow arbitrary code execution in the context of the logged-on user, potentially enabling an attacker to install programs, manipulate or delete data, or create new accounts with full user rights. The impact scales with the privileges of the compromised account, meaning systems where users operate with administrative rights face greater risk.

No evidence of in-the-wild exploitation has been reported at this time. Affected versions include Dell Secure Connect Gateway 5.0 Application prior to 5.36.00.00 and the Appliance variant prior to 5.36.00.16. Dell has released updates addressing these issues, and MS-ISAC recommends prompt patching following standard testing procedures, alongside standard defense-in-depth measures such as least-privilege enforcement, application allowlisting, host-based intrusion detection/prevention, and routine vulnerability scanning.

This advisory is largely informational and preventive in nature, targeting organizations running Dell infrastructure management software. Given the absence of active exploitation and the requirement for a logged-on user context, the risk is best characterized as moderate, warranting timely patch management rather than emergency response.

Source reporting: https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-dellsecure-connect-gateway-could-allow-for-arbitrary-code-execution_2026-089

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/2728fa59-97e0-538a-be6d-a55267695c1d/dell-secure-connect-gateway-flaws-enable-code-execution.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
