Advanced Authentication Remediation Guidance for Log4j Vulnerabilities (CVE-2026-34477, CVE-2026-34480, CVE-2025-68161)
search cancel

Advanced Authentication Remediation Guidance for Log4j Vulnerabilities (CVE-2026-34477, CVE-2026-34480, CVE-2025-68161)

book

Article ID: 442854

calendar_today

Updated On:

Products

CA Strong Authentication

Issue/Introduction

Customers using Symantec Advanced Authentication may report security scan flags for the following Apache Log4j vulnerabilities:

  • CVE-2026-34477
  • CVE-2026-34480
  • CVE-2025-68161

Resolution

Following a thorough technical investigation by Broadcom Engineering, it has been determined that Symantec Advanced Authentication is not impacted by CVE-2026-34477, CVE-2026-34480, or CVE-2025-68161.

Recommendation

Although the product is not susceptible to these specific vulnerabilities, Broadcom strongly advises customers to maintain their environment on a supported release to benefit from ongoing security hardening:

  • Target Version: Upgrade to Advanced Authentication 9.1.5.2 or higher.
  • Benefit: This version includes the most recent cumulative security updates and performance improvements.