Is Symantec Protection Engine (SPE) affected by CVE-2026-49844?
SPE 9.3
CVE-2026-49844: SPE is not impacted.
CVE-2026-49844 is a Medium-severity (CVSS 5.9) integrity vulnerability in Apache Log4j that allows a remote, unauthenticated attacker to inject malicious content into structured log output, however, only when following conditions are met:
Both the conditions must hold at the same time for the vulnerable code path to be reached.
Because SPE exclusively employs pattern-based text layouts for its logging configuration, it does not utilize the structured message logging necessary to trigger this vulnerability. As neither precondition for exploitation is satisfied, SPE is not impacted.