Security teams may report concerns regarding vulnerability scans or security advisories identifying CVE-2026-25414.
CVE-2026-35414:
From https://access.redhat.com/security/cve/cve-2026-35414
Description
A flaw was found in OpenSSH. This vulnerability arises from the incorrect handling of the authorized_keys principals option in uncommon scenarios. Specifically, when a principals list is used with a Certificate Authority that includes comma characters, OpenSSH may misinterpret the input. This could lead to security bypasses, potentially allowing unintended access or information disclosure in specific authentication contexts.
Symantec Messaging Gateway is NOT vulnerable to CVE-2026-35414.
This issue is patched in the version of OpenSSH used in Messaging Gateway 10.9.2 and later. Additionally, SMG does not ship with support for SSH certificates enabled.