This article provides a security assessment for Symantec LiveUpdate Administrator (LUA) regarding several high-profile vulnerabilities reported in 2026 affecting libcurl and the Spring Framework.
| libcurl 8.11.0 < 8.21.0 HTTP/3 Early Data Information Disclosure | CVE-2026-9545 |
| Spring Framework 5.3.x < 5.3.49 / 6.1.x < 6.1.28 / 6.2.x < 6.2.18.1 / 7.0.x < 7.0.7.1 Multiple Vulnerabilities | CVE-2026-41841,CVE-2026-41848, |
| Spring Framework 5.3.x < 5.3.49 Multiple Vulnerabilities | CVE-2026-41849,CVE-2026-41847 |
| Libcurl 7.12.0 < 8.21.0 Cross-Proxy Digest Auth State Leak | CVE-2026-8927 |
LUA 2.3.14
LiveUpdate Administrator (LUA) is not impacted by these vulnerabilities as it does not use libcurl, Spring Expression Language (SpEL), WebFlux, routing, the reactive stack, scriptUtils, or user-controlled input for tags.
It is free from all the components that caused these vulnerabilities.
Vulnerability scanners may flag the version numbers of bundled third-party libraries (e.g., libcurl.dll or spring-core-####.jar). However, LUA is not exploitable because it does not utilize the affected modules or features.