• News/
  • bleepingcomputer-20260811110301

Cisco warns of high-severity ClamAV flaws with public exploits

BleepingComputer
·
Sergiu Gatlan
·
Published Aug 11, 2026
·
Updated

Cisco warned of two high-severity vulnerabilities affecting the Secure Endpoint Connector that allow threat actors to crash the ClamAV scanning process in denial-of-service (DoS) attacks. The security flaws (tracked as CVE-2026-20337 and CVE-2026-20338) were found in the ZIP archive parser of ClamAV (Clam AntiVirus), the open-source and cross-platform engine used to scan files for malware. As Cisco explained in a Friday advisory, the two vulnerabilities are due to improper boundary checks and memory handling, respectively, and can be exploited by unauthenticated, remote attackers. The company's Product Security Incident Response Team (PSIRT) added that proof-of-concept (PoC) exploit code is already publicly available, but said that it has no evidence the flaws have been exploited in the wild. "An attacker could exploit this vulnerability by submitting a crafted zip file for scanning. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software," it said. "The Cisco PSIRT is aware that proof-of-concept exploit code is available for the vulnerabilities that are described in CVE-2026-20337 and CVE-2026-20338." Cisco added that the flaws' security impact is high only for Windows platforms since they're the only ones that "run the ClamAV scanning process in a privileged security context." These two vulnerabilities affect ClamAV 1.5.0 through 1.5.3, and they were patched in version 1.5.4 rele...

Read full article

Affected Software

2 affected components
Cisco Secure Endpoint Connector>=1.5.0<1.5.4
Clam AntiVirus (ClamAV) ClamAV>=1.5.0<=1.5.3
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses two high-severity vulnerabilities in the ClamAV scanning process as warned by Cisco.

2

What security implications are discussed in the article?

The vulnerabilities allow threat actors to execute denial-of-service (DoS) attacks by crashing the ClamAV scanning process.

3

What are the identifiers for the vulnerabilities mentioned?

The vulnerabilities are tracked as CVE-2026-20337 and CVE-2026-20338.

4

Which products are affected by these vulnerabilities?

The affected products include Cisco Secure Endpoint Connector and ClamAV (Clam AntiVirus).

5

What immediate action is suggested for users of the affected software?

Users should be aware that exploits are publicly available, indicating a need to apply security measures promptly.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203