Dell issued security advisories DSA-2026-385, DSA-2026-404, DSA-2026-408, and DSA-2026-410 for multiple vulnerabilities affecting Rugged Control Center, Secure Connect Gateway Policy Manager, ThinOS 10, and Trusted Device Client. The issues affect Rugged Control Center versions earlier than 5.2.206, Secure Connect Gateway Policy Manager versions earlier than 5.36.00.16, ThinOS 10 releases before SecurityAddon_2605.10.2766_T10, and Trusted Device Client versions before 8.1.359.0.
The Trusted Device Client flaws include an incorrect permission assignment for a critical resource, which could expose affected endpoints to unauthorized access or misuse of protected resources depending on local conditions. The Canadian Centre for Cyber Security and Guyana National CIRT urged administrators to review Dell’s advisories, identify affected deployments, and apply the relevant vendor updates promptly.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
The Canadian Centre for Cyber Security issued advisory AV26-966 covering the Dell product vulnerabilities and advised users and administrators to review Dell's advisories and apply available updates.
Dell reported multiple vulnerabilities affecting Rugged Control Center before 5.2.206, Secure Connect Gateway Policy Manager before 5.36.00.16, ThinOS 10 before SecurityAddon_2605.10.2766_T10, and Trusted Device Client before 8.1.359.0. The issues are addressed in advisories DSA-2026-410, DSA-2026-385, DSA-2026-404, and DSA-2026-408, respectively; the Trusted Device Client issue is an incorrect permission assignment for a critical resource.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcecyber.gc.ca
Open sourcecirt.gy
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.