Impact of CVE-2026-41862 on Endpoint Protection
search cancel

Impact of CVE-2026-41862 on Endpoint Protection

book

Article ID: 447650

calendar_today

Updated On:

Products

Endpoint Protection

Issue/Introduction

Is Symantec Endpoint Protection (SEP) or Symantec Endpoint Protection Manager (SEPM) vulnerable to CVE-2026-41862?

Environment

  • Symantec Endpoint Protection Manager 14.3.x
  • Symantec Endpoint Protection Agent 14.3.x (Windows, Mac, Linux)

Resolution

SEPM and SEP client are not impacted by CVE-2026-41862 as follows:

  • CVE-2026-41862 is a deserialization vulnerability specifically affecting the Spring Statemachine component.
  • SEPM: The Spring Statemachine library is not included in the SEPM installation and is not utilized by the manager’s services or web console.
  • SEP Agent: The SEP client (all platforms) does not package or use the Spring Statemachine component for its operations.