Is Messaging Gateway vulnerable to CVE-2026-35387?
search cancel

Is Messaging Gateway vulnerable to CVE-2026-35387?

book

Article ID: 445527

calendar_today

Updated On:

Products

Messaging Gateway

Issue/Introduction

Security teams may report concerns regarding vulnerability scans or security advisories identifying CVE-2026-35387.

CVE-2026-35387:

From https://access.redhat.com/security/cve/cve-2026-35387  -

Low severity

Description

A flaw was found in OpenSSH. This vulnerability allows the system to use unintended Elliptic Curve Digital Signature Algorithm (ECDSA) algorithms. This occurs because the configuration for accepted public key algorithms is misinterpreted, leading to the use of weaker cryptographic methods than intended. This could potentially allow an attacker to compromise the confidentiality of data.

Environment

  • Product: Messaging Gateway
  • Version: 10.9.2 and later

Resolution

Symantec Messaging Gateway is NOT vulnerable to CVE-2026-35387.

This issue is patched in the version of OpenSSH used to Messaging Gateway 10.9.2 and later. Additionally, Messaging Gateway does not provide a means by which an administrator can import ECDSA public keys so there is no path to exploit 

Additional Information