Cisco's ClamAV Flaws Can Knock Out Endpoint Scanning

Cisco warned Friday that Secure Endpoint Connector for Windows, macOS, and Linux is exposed to seven ClamAV parser flaws, including CVE-2026-20337 and CVE-2026-20338, and said both ZIP bugs already have public proof-of-concept code. Cisco plans to roll out updates in August, and it says no workaround exists. The bugs live in ClamAV’s file parsers, so a crafted archive can crash the scanner while it is inspecting content instead of simply flagging a bad file. On Windows, Cisco says that scanner runs in a privileged security context, which makes the outage more disruptive because the trusted control itself goes down rather than just one local utility. Cisco and CSIRT Italia disagree on Secure Endpoint Private Cloud: Cisco says it is out of scope, while the Italian advisory lists Private Cloud 4.2.x before 4.2.8 as affected. If ClamAV sits inline as the gatekeeper for endpoint files, the exposure is in the scanning layer itself, not only in the file being checked.

Part of the PlainSec briefing for 2026-08-11

Every edition of this story: Cisco's ClamAV Flaws Can Knock Out Endpoint Scanning

Sources