Customers evaluating the security posture of Symantec Protection Engine (SPE) 9.3.1 may need to determine if their environment is affected by CVE-2026-40984, CVE-2026-40983, and CVE-2026-9370. This article provides technical clarification regarding the impact of these specific CVEs on the SPE software.
SPE 9.3.1
Symantec Protection Engine (SPE) 9.3.1 is not impacted by these vulnerabilities. The technical assessment findings are as follows:
micrometer, is included within SPE solely as a transitive dependency of spring.boot. Because this component is neither imported nor utilized within the SPE codebase, SPE is not impacted by these CVEs.SimpleGCMConfig and is therefore not impacted by this CVE.