Assessment Regarding CVE-2026-40984, CVE-2026-40983, and CVE-2026-9370
search cancel

Assessment Regarding CVE-2026-40984, CVE-2026-40983, and CVE-2026-9370

book

Article ID: 452159

calendar_today

Updated On:

Products

Protection Engine for Cloud Services Protection Engine for NAS

Issue/Introduction

Customers evaluating the security posture of Symantec Protection Engine (SPE) 9.3.1 may need to determine if their environment is affected by CVE-2026-40984, CVE-2026-40983, and CVE-2026-9370. This article provides technical clarification regarding the impact of these specific CVEs on the SPE software.

Environment

SPE 9.3.1

Resolution

Symantec Protection Engine (SPE) 9.3.1 is not impacted by these vulnerabilities. The technical assessment findings are as follows:

  1. CVE-2026-40984 and CVE-2026-40983: The component in question, micrometer, is included within SPE solely as a transitive dependency of spring.boot. Because this component is neither imported nor utilized within the SPE codebase, SPE is not impacted by these CVEs.
  2. CVE-2026-9370: The SPE software does not utilize the class SimpleGCMConfig and is therefore not impacted by this CVE.