CVE-2018-12243: Symantec Messaging Gateway

High severity, CVSS 8.8. EPSS: 0.8% chance of exploitation in the next 30 days.

The Symantec Messaging Gateway product prior to 10.6.6 may be susceptible to a XML external entity (XXE) exploit, which is a type of issue where XML input containing a reference to an external entity is processed by a weakly configured XML parser. The attack uses file URI schemes or relative paths in the system identifier to access files that should not normally be accessible.

Affected products

  • Symantec Messaging Gateway: before 10.6.6 (fixed in 10.6.6)

Published 2018-09-19. Last modified 2026-06-17.