Security teams may report concerns regarding vulnerability scans or security advisories identifying CVE-2026-35388.
CVE-2026-35388:
From https://access.redhat.com/security/cve/cve-2026-35388
Description
A flaw was found in OpenSSH. This vulnerability allows for a low integrity impact due to the omission of connection multiplexing confirmation for proxy-mode multiplexing sessions. A local user, under specific and complex conditions requiring user interaction, could potentially establish a multiplexed session without explicit confirmation, leading to unintended data handling.
Symantec Messaging Gateway is NOT vulnerable to CVE-2026-35388.
This issue is patched in the version of OpenSSH used in Messaging Gateway 10.9.2 and later. Additionally, Messaging Gateway does not allow the local admin account to modify the ssh config file to allow for multiplexed sessions.