Security teams may report concerns regarding vulnerability scans or security advisories identifying CVE-2026-35387.
CVE-2026-35387:
From https://access.redhat.com/security/cve/cve-2026-35387 -
Low severity
Description
A flaw was found in OpenSSH. This vulnerability allows the system to use unintended Elliptic Curve Digital Signature Algorithm (ECDSA) algorithms. This occurs because the configuration for accepted public key algorithms is misinterpreted, leading to the use of weaker cryptographic methods than intended. This could potentially allow an attacker to compromise the confidentiality of data.
Symantec Messaging Gateway is NOT vulnerable to CVE-2026-35387.
This issue is patched in the version of OpenSSH used to Messaging Gateway 10.9.2 and later. Additionally, Messaging Gateway does not provide a means by which an administrator can import ECDSA public keys so there is no path to exploit