Cisco warned of two high-severity vulnerabilities affecting the Secure Endpoint Connector that allow threat actors to crash the ClamAV scanning process in denial-of-service (DoS) attacks. The security flaws (tracked as CVE-2026-20337 and CVE-2026-20338) were found in the ZIP archive parser of ClamAV (Clam AntiVirus), the open-source and cross-platform engine used to scan files for malware. As Cisco explained in a Friday advisory, the two vulnerabilities are due to improper boundary checks and memory handling, respectively, and can be exploited by unauthenticated, remote attackers. The company's Product Security Incident Response Team (PSIRT) added that proof-of-concept (PoC) exploit code is already publicly available, but said that it has no evidence the flaws have been exploited in the wild. "An attacker could exploit this vulnerability by submitting a crafted zip file for scanning. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software," it said. "The Cisco PSIRT is aware that proof-of-concept exploit code is available for the vulnerabilities that are described in CVE-2026-20337 and CVE-2026-20338." Cisco added that the flaws' security impact is high only for Windows platforms since they're the only ones that "run the ClamAV scanning process in a privileged security context." These two vulnerabilities affect ClamAV 1.5.0 through 1.5.3, and they were patched in version 1.5.4 rele...
Cisco warns of high-severity ClamAV flaws with public exploits
BleepingComputer
·Sergiu Gatlan
·Published Aug 11, 2026
·Updated
Affected Software
2 affected components
Cisco Secure Endpoint Connector>=1.5.0<1.5.4
Clam AntiVirus (ClamAV) ClamAV>=1.5.0<=1.5.3
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses two high-severity vulnerabilities in the ClamAV scanning process as warned by Cisco.
2
What security implications are discussed in the article?
The vulnerabilities allow threat actors to execute denial-of-service (DoS) attacks by crashing the ClamAV scanning process.
3
What are the identifiers for the vulnerabilities mentioned?
The vulnerabilities are tracked as CVE-2026-20337 and CVE-2026-20338.
4
Which products are affected by these vulnerabilities?
The affected products include Cisco Secure Endpoint Connector and ClamAV (Clam AntiVirus).
5
What immediate action is suggested for users of the affected software?
Users should be aware that exploits are publicly available, indicating a need to apply security measures promptly.