Is Messaging Gateway vulnerable to CVE-2026-35388?
search cancel

Is Messaging Gateway vulnerable to CVE-2026-35388?

book

Article ID: 445531

calendar_today

Updated On:

Products

Messaging Gateway

Issue/Introduction

Security teams may report concerns regarding vulnerability scans or security advisories identifying CVE-2026-35388.

CVE-2026-35388:

From https://access.redhat.com/security/cve/cve-2026-35388

Description

A flaw was found in OpenSSH. This vulnerability allows for a low integrity impact due to the omission of connection multiplexing confirmation for proxy-mode multiplexing sessions. A local user, under specific and complex conditions requiring user interaction, could potentially establish a multiplexed session without explicit confirmation, leading to unintended data handling.

Environment

  • Product: Messaging Gateway (SMG)
  • Version: 10.9.2 and later

Resolution

Symantec Messaging Gateway is NOT vulnerable to CVE-2026-35388.

This issue is patched in the version of OpenSSH used in Messaging Gateway 10.9.2 and later. Additionally, Messaging Gateway does not allow the local admin account to modify the ssh config file to allow for multiplexed sessions.

Additional Information