Vulnerabilities · 71 days ago
ClamAV’s file inspection code is part of the attack surface. A crafted archive, executable, or DMG can trip a parser bug during scanning and crash the scanner or corrupt memory, so gateways and endpoint tools that rely on ClamAV inherit risk from the security control itself.
Cisco shipped ClamAV 1.5.3 and 1.4.5 to fix seven parser flaws: CVE-2026-20213, CVE-2026-20214, CVE-2026-20215, CVE-2026-20216, CVE-2026-20217, CVE-2026-20243, and CVE-2026-20244. The bugs sit in packer, archive, and DMG code, and some traces back to 2004 and 2005. One fix also hardens quarantine handling against TOCTOU races in clamscan, clamdscan, and clamonacc.
CVEs in this update
7 CVEs
Across azl3 clamav 1.5.2-3 on Azure Linux 3.0.
0 critical · 7 high · 0 medium · 0 low
0 in CISA KEV · 0 with EPSS above 1%
Highest severity: CVE-2026-20213 · 7.5 HIGH
3 sources covering this story
New ClamAV security patch closes seven scanner bugs dating back two decades - Help Net Security
The ClamAV security patch ships versions 1.5.3 and 1.4.5, fixing seven CVEs in packer, archive, and DMG parsers dating back two decades.
Risolte vulnerabilità in ClamAV
Rilasciato un aggiornamento di sicurezza che mira a sanare sette vulnerabilità, con gravità “alta”, relativamente al prodotto ClamAV di Cisco.
Cisco Security Advisory: ClamAV Vulnerabilities Affecting Cisco Products: July 2026
For additional information on these vulnerabilities in ClamAV, see the ClamAV blog.
Part of the PlainSec briefing for 2026-07-06