CVE-2026-3862: Broadcom Symantec Siteminder

Medium severity, CVSS 4.8. EPSS: 0.3% chance of exploitation in the next 30 days.

Cross-site Scripting (XSS) allows an attacker to submit specially crafted data to the application which is returned unaltered in the resulting web page.

Affected products

  • Broadcom Symantec Siteminder: from 12.8, up to and including 12.8.08; version 12.9 only

Published 2026-03-10. Last modified 2026-06-17.