Is Messaging Gateway vulnerable to CVE-2026-35414?
search cancel

Is Messaging Gateway vulnerable to CVE-2026-35414?

book

Article ID: 445535

calendar_today

Updated On:

Products

Messaging Gateway

Issue/Introduction

Security teams may report concerns regarding vulnerability scans or security advisories identifying CVE-2026-25414.

CVE-2026-35414:

From https://access.redhat.com/security/cve/cve-2026-35414

Description

A flaw was found in OpenSSH. This vulnerability arises from the incorrect handling of the authorized_keys principals option in uncommon scenarios. Specifically, when a principals list is used with a Certificate Authority that includes comma characters, OpenSSH may misinterpret the input. This could lead to security bypasses, potentially allowing unintended access or information disclosure in specific authentication contexts.

 

Environment

  • Product: Messaging Gateway (SMG)
  • Version: 10.9.2 and later

Resolution

Symantec Messaging Gateway is NOT vulnerable to CVE-2026-35414.

This issue is patched in the version of OpenSSH used in Messaging Gateway 10.9.2 and later. Additionally, SMG does not ship with support for SSH certificates enabled.

Additional Information