Cisco Reports Seven High-Severity ClamAV Flaws: Two PoCs Available
Cisco recently reported seven vulnerabilities in ClamAV parsers, the open-source engine used by Secure Endpoint Connector on Windows, macOS, and Linux .
Illustrative image generated with AI
Vulnerabilities Affect Secure Endpoint Connector
Cisco recently reported seven vulnerabilities in ClamAV parsers, the open-source engine used by Secure Endpoint Connector on Windows, macOS, and Linux.
The flaws, tracked as CVE-2026-20337, CVE-2026-20338, CVE-2026-20339, CVE-2026-20345, CVE-2026-20346, CVE-2026-20347, and CVE-2026-20348, can cause denial-of-service conditions when scanning specially crafted files.
The vulnerabilities affect ClamAV parsers for the following formats:
- ZIP;
- GPT;
- PESpin;
- PDF;
- Mach-O;
- XAR.
Public proof-of-concept exploits are already available for CVE-2026-20337 and CVE-2026-20338. Cisco says, however, that it has found no evidence of real-world exploitation.
Higher Risk on Windows Endpoints
The impact varies by operating system. On Windows, the risk is considered high because the ClamAV scanning process runs with elevated security privileges.
On macOS and Linux, the risk is considered medium because the affected component runs with lower privileges. The primary impact is the blocking or interruption of the scanning process, not direct code execution through the seven ClamAV flaws.
The vulnerability does not affect Secure Endpoint Private Cloud. The affected component is Secure Endpoint Connector, which is installed on endpoints.
ClamAV 1.5.4 Patch and Cisco Updates
The fixes are included in ClamAV 1.5.4. This release also addresses a path traversal vulnerability in WinRAR handling on Windows that could allow arbitrary code execution.
Cisco will distribute fixes for Secure Endpoint Connector products in August. Organizations should apply the patches to their endpoints as soon as they become available.
The fixes are also included in Secure Endpoint Private Cloud 4.2.8 and later. Starting with these releases, they can be distributed from the cloud to connected devices.
No Workaround Available
No workarounds have been provided for any of the seven vulnerabilities. In the absence of alternative mitigations, the recommended action is to update the component to a fixed version.
Administrators should verify the version of Secure Endpoint Connector installed on Windows, macOS, and Linux, check for Cisco updates, and pay particular attention to Windows endpoints exposed to scans of untrusted files.
Sources
This article is an original reworking based on the sources below.
CVEs covered in this article
- CVE-2026-20337High7.5A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper boundary checks for content in zip files during scanning, which may result in an out-of-bounds write condition.
- CVE-2026-20338High7.5A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper memory handling when processing content in zip files during scanning. An attacker could exploit this vulnerabil
- CVE-2026-20339High7.5A vulnerability in the PESpin file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in
- CVE-2026-20345High7.5A vulnerability in the GPT file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device. This vulnerability is due to improper handling of an endian conversion o
- CVE-2026-20346High7.5A vulnerability in the PDF file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in PDF
- CVE-2026-20347High7.5A vulnerability in the Mach-O file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in
- CVE-2026-20348High7.5A vulnerability in the XAR file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in XAR




