Is Symantec Messaging Gateway (SMG) vulnerable to CVE-2026-46300?
Broadcom has received inquiries regarding a potential vulnerability (CVE-2026-46300) that could allow for unauthorized code execution. This article provides the current assessment and impact for SMG customers.
Version: 10.9.2 and later
Broadcom engineering has confirmed that Symantec Messaging Gateway is not vulnerable to CVE-2026-46300 in the product's shipped configuration.
The vulnerability is considered unexploitable on the SMG appliance due to the following security controls:
While the current version is not vulnerable, Broadcom will update the SMG kernel in the upcoming version 10.9.3 release. This proactive update is intended to address theoretical findings and ensure the product remains clear of future security scan flags related to this CVE.