You request to know if the Symantec Protection Engine (SPE) is impacted by the following CVEs:
SPE version 9.3.1
Although SPE utilizes jackson-databind, the mandatory precondition for exploitation—Jackson polymorphic type deserialization—is not present in SPE's implementation. Therefore, SPE is not impacted by CVE-2026-54512, CVE-2026-54513, or CVE-2026-54514.