Is Messaging Gateway vulnerable to CVE-2026-33116?
search cancel

Is Messaging Gateway vulnerable to CVE-2026-33116?

book

Article ID: 442626

calendar_today

Updated On:

Products

Messaging Gateway

Issue/Introduction

A concern has been raised regarding whether the Symantec Messaging Gateway (SMG) is vulnerable to CVE-2026-33116.

CVE-2026-33116 identifies an improper input validation vulnerability (resulting in an "infinite loop") within Microsoft .NET, .NET Framework, and Visual Studio. This vulnerability could allow an unauthorized attacker to cause a denial of service (DoS) over a network.

Environment

  • Version: 10.8.x, 10.9.x
  • Platform: Hardware, Virtual Infrastructure

Resolution

Symantec Messaging Gateway is not vulnerable to CVE-2026-33116.

Symantec Messaging Gateway is a hardened Linux-based appliance. It does not utilize the Microsoft .NET Framework for its core messaging processing, scanner services, or the Control Center management interface.

Because the affected software component (.NET Framework) is not present or used within the SMG appliance architecture, the vulnerability cannot be exploited on the SMG platform.

No action is required by administrators regarding this specific CVE.

Additional Information