Is Data Center Security affected by CVE-2026-23918, CVE-2026-24072, CVE-2026-29169 and CVE-2026-34059
search cancel

Is Data Center Security affected by CVE-2026-23918, CVE-2026-24072, CVE-2026-29169 and CVE-2026-34059

book

Article ID: 441699

calendar_today

Updated On:

Products

Data Center Security Server Advanced

Issue/Introduction

Whether Symantec Data Center Security (DCS) is affected by specific Apache HTTP Server vulnerabilities reported by security scanners or advisories, including:

  • CVE-2026-23918: Double-free memory corruption in mod_http2.
  • CVE-2026-24072: Unauthorized file access via .htaccess.
  • CVE-2026-29169
  • CVE-2026-34059

Environment

Data Center Security (DCS) 6.10.x

Cause

These vulnerabilities specifically impact the Apache HTTP Server (typically version 2.4.66 and earlier modules). DCS does not utilize the Apache HTTP Server for its management console or hosting services.

Resolution

Symantec Data Center Security (DCS) are not affected by these vulnerabilities.

DCS utilize Apache Tomcat for web hosting and management services rather than the Apache HTTP Server. Because the vulnerable modules (such as mod_http2) are not part of the DCS architecture, there is no exposure to these specific CVEs.