Query regarding impact of CVE-2026-23666 on Messaging Gateway
search cancel

Query regarding impact of CVE-2026-23666 on Messaging Gateway

book

Article ID: 442622

calendar_today

Updated On:

Products

Messaging Gateway

Issue/Introduction

The security team for a customer wants to know if Symantec Messaging Gateway (SMG) is vulnerable to CVE-2026-23666 in any supported configuration.

CVE-2026-23666 is a vulnerability identified as improper input validation within the Microsoft .NET Framework that could allow an unauthorized attacker to cause a denial of service (DoS) over a network.

Environment

  • Version: 10.8.x, 10.9.x

Resolution

Symantec Messaging Gateway is not vulnerable to CVE-2026-23666.

Symantec Messaging Gateway is a hardened Linux-based appliance. It does not utilize the Microsoft .NET Framework for its core messaging processing, scanner services, or the Control Center management interface. Because the affected software component (.NET Framework) is not present or used within the SMG appliance architecture, the vulnerability cannot be exploited.

No action is required by administrators regarding this specific CVE.

Additional Information