Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC
Remote, unauthenticated attackers could exploit the bugs to cause a denial-of-service (DoS) condition. The post Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC appeared first on SecurityWeek .
AI Analysis
Technical Summary
Cisco disclosed seven vulnerabilities in ClamAV, tracked as CVE-2026-20337 to CVE-2026-20339 and CVE-2026-20345 to CVE-2026-20348, affecting its Secure Endpoint Connector on Windows, macOS, and Linux. These flaws reside in ClamAV's file format parsers for ZIP, GPT, PESpin, PDF, Mach-O, and XAR, enabling remote unauthenticated attackers to trigger denial-of-service conditions. Two vulnerabilities have public proof-of-concept code available. ClamAV version 1.5.4 includes patches for these issues, alongside a fix for a related WinRAR path traversal vulnerability. Cisco plans to distribute security updates for its Secure Endpoint Connector products in August. The vulnerabilities pose a high risk on Windows due to privileged scanning processes, and medium risk on macOS and Linux where scanning runs with lower privileges. Secure Endpoint Private Cloud is unaffected. No known active exploitation has been reported.
Potential Impact
The vulnerabilities allow remote, unauthenticated attackers to cause denial-of-service conditions on affected systems running Cisco Secure Endpoint Connector with ClamAV. On Windows, the impact is higher severity because the scanning process runs with elevated privileges, potentially causing more significant disruption. On macOS and Linux, the impact is medium severity due to lower privilege execution of the scanning process. There is no indication of code execution or data compromise from these vulnerabilities. No active exploitation in the wild has been observed.
Mitigation Recommendations
Patches addressing these vulnerabilities are available in ClamAV version 1.5.4 and will be rolled out by Cisco for Secure Endpoint Connector products in August. Customers should apply these updates promptly once released. No workarounds exist for these vulnerabilities. Secure Endpoint Private Cloud customers should ensure they are running release 4.2.8 or later, which includes the fixes. Cisco advises pushing the available patches from the cloud to endpoints. Monitoring or other mitigations are not specifically recommended by Cisco.
Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC
Description
Remote, unauthenticated attackers could exploit the bugs to cause a denial-of-service (DoS) condition. The post Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC appeared first on SecurityWeek .
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Cisco disclosed seven vulnerabilities in ClamAV, tracked as CVE-2026-20337 to CVE-2026-20339 and CVE-2026-20345 to CVE-2026-20348, affecting its Secure Endpoint Connector on Windows, macOS, and Linux. These flaws reside in ClamAV's file format parsers for ZIP, GPT, PESpin, PDF, Mach-O, and XAR, enabling remote unauthenticated attackers to trigger denial-of-service conditions. Two vulnerabilities have public proof-of-concept code available. ClamAV version 1.5.4 includes patches for these issues, alongside a fix for a related WinRAR path traversal vulnerability. Cisco plans to distribute security updates for its Secure Endpoint Connector products in August. The vulnerabilities pose a high risk on Windows due to privileged scanning processes, and medium risk on macOS and Linux where scanning runs with lower privileges. Secure Endpoint Private Cloud is unaffected. No known active exploitation has been reported.
Potential Impact
The vulnerabilities allow remote, unauthenticated attackers to cause denial-of-service conditions on affected systems running Cisco Secure Endpoint Connector with ClamAV. On Windows, the impact is higher severity because the scanning process runs with elevated privileges, potentially causing more significant disruption. On macOS and Linux, the impact is medium severity due to lower privilege execution of the scanning process. There is no indication of code execution or data compromise from these vulnerabilities. No active exploitation in the wild has been observed.
Mitigation Recommendations
Patches addressing these vulnerabilities are available in ClamAV version 1.5.4 and will be rolled out by Cisco for Secure Endpoint Connector products in August. Customers should apply these updates promptly once released. No workarounds exist for these vulnerabilities. Secure Endpoint Private Cloud customers should ensure they are running release 4.2.8 or later, which includes the fixes. Cisco advises pushing the available patches from the cloud to endpoints. Monitoring or other mitigations are not specifically recommended by Cisco.
Technical Details
- Classification
- {"confidence":0.75,"severitySource":"stated","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.securityweek.com/cisco-warns-of-high-severity-clamav-vulnerabilities-with-public-poc/","fetched":true,"fetchedAt":"2026-08-10T14:11:13.189Z","wordCount":965}
Threat ID: 6a79dc01bf8831d539cf1cec
Added to database: 08/10/2026, 14:11:13 UTC
Last enriched: 08/10/2026, 14:11:40 UTC
Last updated: 08/10/2026, 22:33:49 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.