Vulnerability impact on Symantec Endpoint Protection Manager
search cancel

Vulnerability impact on Symantec Endpoint Protection Manager

book

Article ID: 447979

calendar_today

Updated On:

Products

Endpoint Protection

Issue/Introduction

To check whether Symantec Endpoint Protection Manager (SEPM), Symantec Endpoint Protection, Live Update Administrator(LUA) are impacted with the below vulnerabilities:

CVE-2026-40988
CVE-2026-40993
CVE-2026-41003
CVE-2026-41695
CVE-2026-41716

Environment

 

  • Symantec Endpoint Protection Manager (SEPM) version: 14.3 RU9
  • Symantec Endpoint Protection  version:14.3 RU9
  • LUA 2.3.14

Resolution

  • CVE-2026-40988: No impact, SEPM doesn't use spring-security-saml2-service-provider.
  • CVE-2026-40993: No impact, SEPM doesn't contain a SAML 2.0 implementation in its Spring components.
  • CVE-2026-41003: No impact, SEPM doesn't contain a SAML 2.0 implementation in Spring components.
  • CVE-2026-41695: No impact, SEPM uses Spring Data Commons v1.4.1 which is not in the affected version ranges.
  • CVE-2026-41716: No impact, SEPM uses Spring Data Commons v1.4.1 which is not in the affected version ranges.

SEP client and LUA are not impacted as these products do not utilize the affected components