Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4356 articles · 196341 vulns · 36/41 feeds (7d)
← Back to list
9.0
CVE-2026-15380PATCHED
broadcom · symantec management suite

Local privilege escalation in Symantec ITMS

Description

A non-administrator interactive user can obtain full SYSTEM code execution through a DCOM/task scheduler logic chain — no network access, no memory corruption required (ITMS 8.7.3)

Affected Products

VendorProductVersions
broadcomsymantec management suitebefore SMA_SMP_8_8_PF_v13 and SMA_SMP_8_8_1_PF_v5

References

  • https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37995(vendor-advisory)

Related News (1 articles)

Tier C
VulDB38d ago
CVE-2026-15380 | Broadcom Symantec Management Suite 8.7.3/8.8/8.8.1 Task Scheduler Local Privilege Escalation
→ No new info (linked only)
CVSS 3.19.0 NONE
CISA KEV❌ No
Actively exploited❌ No
Patch available
https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37995
PublishedJul 17, 2026
Last enriched38d agov2
Trending Score0
Source articles1
Independent1
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-57220
RabbitMQ: Stream listener does not enforce configured frame-size limit during authentication, permitting unauth'd mem-exhaust DoS
Trending: 1
CRITICALPRE-CVE
Multiple vulnerabilities in Broadcom VMware Tanzu Greenplum and RabbitMQ products
CRITICALPRE-CVE
Critical Vulnerabilities in VMware Tanzu for MySQL on Kubernetes
NONECVE-2026-15379
Arbitrary File Read as SYSTEM in Symantec ITMS
NONECVE-2026-11626
Local Privilege Escalation in Symantec Endpoint Protection macOS CleanWipe Removal Tool

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 17, 2026
Discovered by ZDM
Jul 17, 2026
Updated: severity, cvssEstimate, cweIds
Jul 17, 2026
Patch Available
Jul 21, 2026

Version History

v2
Last enriched 38d ago
v2Tier C38d ago

Updated severity from NONE to CRITICAL based on 'very critical' rating; assigned CVSS estimate of 9.0 and CWE-269 (Improper Access Control / Privilege Management)

severitycvssEstimatecweIds
via VulDB
v138d ago

Initial creation