Cisco warns of high-severity ClamAV flaws with public exploits
Cisco has disclosed two high-severity vulnerabilities in the ClamAV scanning engine used by its Secure Endpoint Connector. These flaws allow unauthenticated remote attackers to crash the ClamAV scanning process by submitting specially crafted ZIP files, causing denial-of-service (DoS) conditions. The vulnerabilities affect ClamAV versions 1.5.0 through 1.5.3 and were patched in version 1.5.4. The impact is particularly significant on Windows platforms where ClamAV runs with privileged security context. Proof-of-concept exploit code is publicly available, but there is no evidence of active exploitation in the wild. Cisco plans to release updates for affected Secure Endpoint Connector versions across Windows, Linux, and Mac platforms. No workarounds exist for these vulnerabilities.
AI Analysis
Technical Summary
Two high-severity vulnerabilities (CVE-2026-20337 and CVE-2026-20338) were found in the ZIP archive parser of ClamAV, an open-source antivirus engine used by Cisco Secure Endpoint Connector. The flaws stem from improper boundary checks and memory handling, enabling unauthenticated remote attackers to submit crafted ZIP files that crash the ClamAV scanning process, resulting in denial-of-service. These vulnerabilities affect ClamAV versions 1.5.0 through 1.5.3 and were fixed in version 1.5.4 released on August 7, 2026. Cisco highlighted that the security impact is highest on Windows due to privileged execution context. Proof-of-concept exploit code is publicly available, but no active exploitation has been observed. Cisco is preparing updates for Secure Endpoint Connector on multiple platforms to address these issues. No workarounds are available.
Potential Impact
Successful exploitation causes the ClamAV scanning process to terminate, resulting in denial-of-service conditions on affected systems. On Windows platforms, where ClamAV runs with elevated privileges, the impact is considered high. The vulnerabilities do not provide code execution or data compromise but disrupt malware scanning capabilities, potentially allowing malware to evade detection temporarily. There is no evidence of exploitation in the wild despite public availability of proof-of-concept code.
Mitigation Recommendations
These vulnerabilities were patched in ClamAV version 1.5.4 released on August 7, 2026. Cisco plans to release Secure Endpoint Connector updates for Windows, Linux, and Mac later in the month to address these flaws. There are no workarounds for these issues. Organizations should apply the ClamAV 1.5.4 update promptly and monitor Cisco advisories for the forthcoming Secure Endpoint Connector patches. Patch status is confirmed by Cisco's advisory.
Cisco warns of high-severity ClamAV flaws with public exploits
Description
Cisco has disclosed two high-severity vulnerabilities in the ClamAV scanning engine used by its Secure Endpoint Connector. These flaws allow unauthenticated remote attackers to crash the ClamAV scanning process by submitting specially crafted ZIP files, causing denial-of-service (DoS) conditions. The vulnerabilities affect ClamAV versions 1.5.0 through 1.5.3 and were patched in version 1.5.4. The impact is particularly significant on Windows platforms where ClamAV runs with privileged security context. Proof-of-concept exploit code is publicly available, but there is no evidence of active exploitation in the wild. Cisco plans to release updates for affected Secure Endpoint Connector versions across Windows, Linux, and Mac platforms. No workarounds exist for these vulnerabilities.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Two high-severity vulnerabilities (CVE-2026-20337 and CVE-2026-20338) were found in the ZIP archive parser of ClamAV, an open-source antivirus engine used by Cisco Secure Endpoint Connector. The flaws stem from improper boundary checks and memory handling, enabling unauthenticated remote attackers to submit crafted ZIP files that crash the ClamAV scanning process, resulting in denial-of-service. These vulnerabilities affect ClamAV versions 1.5.0 through 1.5.3 and were fixed in version 1.5.4 released on August 7, 2026. Cisco highlighted that the security impact is highest on Windows due to privileged execution context. Proof-of-concept exploit code is publicly available, but no active exploitation has been observed. Cisco is preparing updates for Secure Endpoint Connector on multiple platforms to address these issues. No workarounds are available.
Potential Impact
Successful exploitation causes the ClamAV scanning process to terminate, resulting in denial-of-service conditions on affected systems. On Windows platforms, where ClamAV runs with elevated privileges, the impact is considered high. The vulnerabilities do not provide code execution or data compromise but disrupt malware scanning capabilities, potentially allowing malware to evade detection temporarily. There is no evidence of exploitation in the wild despite public availability of proof-of-concept code.
Mitigation Recommendations
These vulnerabilities were patched in ClamAV version 1.5.4 released on August 7, 2026. Cisco plans to release Secure Endpoint Connector updates for Windows, Linux, and Mac later in the month to address these flaws. There are no workarounds for these issues. Organizations should apply the ClamAV 1.5.4 update promptly and monitor Cisco advisories for the forthcoming Secure Endpoint Connector patches. Patch status is confirmed by Cisco's advisory.
Technical Details
- Classification
- {"confidence":0.73,"severitySource":"stated","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.bleepingcomputer.com/news/security/cisco-warns-of-high-severity-clamav-flaws-with-public-exploits/","fetched":true,"fetchedAt":"2026-08-11T11:11:14.359Z","wordCount":662}
Threat ID: 6a7b0352bf8831d5399bf663
Added to database: 08/11/2026, 11:11:14 UTC
Last enriched: 08/11/2026, 11:11:25 UTC
Last updated: 08/11/2026, 11:15:55 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.