Impact of CVE-2026-54512, CVE-2026-54513, and CVE-2026-54514 on SPE
search cancel

Impact of CVE-2026-54512, CVE-2026-54513, and CVE-2026-54514 on SPE

book

Article ID: 450274

calendar_today

Updated On:

Products

Protection Engine for Cloud Services Protection Engine for NAS

Issue/Introduction

You request to know if the Symantec Protection Engine (SPE) is impacted by the following CVEs:

  • CVE-2026-54512
  • CVE-2026-54513
  • CVE-2026-54514

Environment

SPE version 9.3.1

Resolution

Although SPE utilizes jackson-databind, the mandatory precondition for exploitation—Jackson polymorphic type deserialization—is not present in SPE's implementation. Therefore, SPE is not impacted by CVE-2026-54512, CVE-2026-54513, or CVE-2026-54514.