Vulnerabilities · 46 days ago
Cisco warned Friday that Secure Endpoint Connector for Windows, macOS, and Linux is exposed to seven ClamAV parser flaws, including CVE-2026-20337 and CVE-2026-20338, and said both ZIP bugs already have public proof-of-concept code. Cisco plans to roll out updates in August, and it says no workaround exists.
The bugs live in ClamAV’s file parsers, so a crafted archive can crash the scanner while it is inspecting content instead of simply flagging a bad file. On Windows, Cisco says that scanner runs in a privileged security context, which makes the outage more disruptive because the trusted control itself goes down rather than just one local utility.
Cisco and CSIRT Italia disagree on Secure Endpoint Private Cloud: Cisco says it is out of scope, while the Italian advisory lists Private Cloud 4.2.x before 4.2.8 as affected. If ClamAV sits inline as the gatekeeper for endpoint files, the exposure is in the scanning layer itself, not only in the file being checked.
CVEs in this update
7 CVEs
0 critical · 7 high · 0 medium · 0 low
0 in CISA KEV · 0 with EPSS above 1%
Highest severity: CVE-2026-20337 · 7.5 HIGH
5 sources covering this story
Zero Day Initiative Advisories
Clam AntiVirus 7z Archive Parsing Integer Overflow Remote Code Execution Vulnerability
Clam AntiVirus 7z Archive Parsing Integer Overflow Remote Code Execution Vulnerability Vulnerability Details This vulnerability allows remote attackers to execute arbitrary code on affected installations of Clam AntiVirus.
Cisco warns of high-severity ClamAV flaws with public exploits
Cisco warned of two high-severity vulnerabilities affecting the Secure Endpoint Connector that allow threat actors to crash the ClamAV scanning process in denial-of-service (DoS) attacks.
Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC
Remote, unauthenticated attackers could exploit the bugs to cause a denial-of-service (DoS) condition.
Risolte vulnerabilità in ClamAV
Aggiornamenti di sicurezza Cisco sanano 7 vulnerabilità con gravità "alta" presenti in ClamAV, software open source per l'analisi antivirus.
Cisco Security Advisory: ClamAV Vulnerabilities Affecting Cisco Products: August 2026
Multiple vulnerabilities in ClamAV could allow a remote attacker to cause a denial of service (DoS) condition, interrupting scanning operations.
Part of the PlainSec briefing for 2026-08-10