Cisco Reports Seven High-Severity ClamAV Flaws: Two PoCs Available

Cisco recently reported seven vulnerabilities in ClamAV parsers, the open-source engine used by Secure Endpoint Connector on Windows, macOS, and Linux .

Cisco Reports Seven High-Severity ClamAV Flaws: Two PoCs Available
Vulnerabilities

Illustrative image generated with AI

Vulnerabilities Affect Secure Endpoint Connector

Cisco recently reported seven vulnerabilities in ClamAV parsers, the open-source engine used by Secure Endpoint Connector on Windows, macOS, and Linux.

The flaws, tracked as CVE-2026-20337, CVE-2026-20338, CVE-2026-20339, CVE-2026-20345, CVE-2026-20346, CVE-2026-20347, and CVE-2026-20348, can cause denial-of-service conditions when scanning specially crafted files.

The vulnerabilities affect ClamAV parsers for the following formats:

  • ZIP;
  • GPT;
  • PESpin;
  • PDF;
  • Mach-O;
  • XAR.

Public proof-of-concept exploits are already available for CVE-2026-20337 and CVE-2026-20338. Cisco says, however, that it has found no evidence of real-world exploitation.

Higher Risk on Windows Endpoints

The impact varies by operating system. On Windows, the risk is considered high because the ClamAV scanning process runs with elevated security privileges.

On macOS and Linux, the risk is considered medium because the affected component runs with lower privileges. The primary impact is the blocking or interruption of the scanning process, not direct code execution through the seven ClamAV flaws.

The vulnerability does not affect Secure Endpoint Private Cloud. The affected component is Secure Endpoint Connector, which is installed on endpoints.

ClamAV 1.5.4 Patch and Cisco Updates

The fixes are included in ClamAV 1.5.4. This release also addresses a path traversal vulnerability in WinRAR handling on Windows that could allow arbitrary code execution.

Cisco will distribute fixes for Secure Endpoint Connector products in August. Organizations should apply the patches to their endpoints as soon as they become available.

The fixes are also included in Secure Endpoint Private Cloud 4.2.8 and later. Starting with these releases, they can be distributed from the cloud to connected devices.

No Workaround Available

No workarounds have been provided for any of the seven vulnerabilities. In the absence of alternative mitigations, the recommended action is to update the component to a fixed version.

Administrators should verify the version of Secure Endpoint Connector installed on Windows, macOS, and Linux, check for Cisco updates, and pay particular attention to Windows endpoints exposed to scans of untrusted files.

Security dossiers

Read next

Sources

This article is an original reworking based on the sources below.

CVEs covered in this article

Back to home

Latest Cybersecurity News

All cybersecurity news →