Cyber Security News

Multiple ClamAV Vulnerabilities Allow Remote Attacker to Trigger DoS Condition

Cisco has disclosed multiple high-severity vulnerabilities in ClamAV that could allow unauthenticated remote attackers to disrupt antivirus scanning operations and cause denial-of-service conditions.

The flaws affect the ClamAV parsers used by Cisco Secure Endpoint Connector on Windows, Linux, and macOS. The advisory, tracked as cisco-sa-clamav-WuuvVd26, was first published on August 7, 2026, and updated on August 10.

Cisco assigned a High security impact rating to affected Windows systems, while Linux and macOS environments received a Medium rating. The company said the difference is due to the privileged security context used by the ClamAV scanning process on Windows devices.

Multiple ClamAV Vulnerabilities

The vulnerabilities include CVE-2026-20337, CVE-2026-20338, CVE-2026-20339, CVE-2026-20345, CVE-2026-20346, CVE-2026-20347, and CVE-2026-20348. Most carry a CVSS score of 7.5 and can be exploited remotely without authentication or user interaction.

Successful exploitation could terminate the ClamAV scanning process, interrupting malware detection and creating a denial-of-service condition.

CVE-2026-20337 is an out-of-bounds write vulnerability in ClamAV’s ZIP archive parser. An attacker could send a specially crafted ZIP file to a vulnerable system for scanning. Improper boundary validation could then cause the scanner process to crash.

CVE-2026-20338 also affects ZIP file processing but is caused by improper memory handling. A crafted archive could trigger a double-free condition, terminating the scanning engine.

Another issue, CVE-2026-20339, affects the PESpin file format parser. The flaw results from insufficient boundary checks, which could lead to an integer overflow during file scanning.

Cisco warned that this issue could cause a denial-of-service attack and may have broader effects due to memory corruption.

CVEVulnerabilityImpact
CVE-2026-20337ZIP parser out-of-bounds writeDoS/crash
CVE-2026-20338ZIP parser double-freeDoS/crash
CVE-2026-20339PESpin parser integer overflowDoS / memory corruption
CVE-2026-20345GPT parser memory corruptionDoS / crash
CVE-2026-20346PDF parser out-of-bounds readDoS / crash
CVE-2026-20347Mach-O parser out-of-bounds readDoS / crash
CVE-2026-20348XAR parser boundary flawDoS / crash

The remaining vulnerabilities affect GPT, PDF, Mach-O, and XAR file parsers. CVE-2026-20345 involves an improper endian conversion when processing GPT files, which may lead to an out-of-bounds buffer write.

CVE-2026-20346 and CVE-2026-20347 affect PDF and Mach-O processing, respectively, allowing out-of-bounds buffer reads. CVE-2026-20348 affects XAR archive handling and is caused by improper boundary checks.

All flaws can be triggered when ClamAV scans attacker-controlled files. This makes email attachments, downloaded archives, shared documents, and files submitted through web applications possible delivery paths, depending on how ClamAV is deployed.

Cisco said the vulnerabilities are independent, meaning exploitation of one flaw is not required to exploit another. Cisco Secure Endpoint Connector for Windows is the most impacted product because the scanner runs in a privileged context.

Secure Endpoint Connector for Linux and Mac are also affected, although their lower-privileged scanning process reduces the security impact.

Cisco Secure Endpoint Private Cloud is not directly vulnerable, but organizations must distribute updated connector software to protected endpoints. Cisco confirmed that no workarounds are available.

Customers should apply the fixed Cisco Secure Endpoint Connector releases through the Secure Endpoint portal when they become available.

Private Cloud customers should ensure they are running version 4.2.8 or later to receive updated connector software through normal content update processes.

Cisco PSIRT is aware of public proof-of-concept exploit code for CVE-2026-20337 and CVE-2026-20338. However, the company said it has not observed malicious exploitation of any of these vulnerabilities in the wild.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.

Abinaya

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Top 10 Best Data Security Posture Management (DSPM) Tools in 2026

DSPM finds sensitive data you didn’t know you had, classifies it, maps who can reach…

2 minutes ago

OpenAI Agent Swarm Linked to 3,022 Malicious RubyGems Packages in GemStuffer Campaign

Open-source packages are meant to save developers time. In the GemStuffer campaign, that trust became…

13 minutes ago

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

5 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

14 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

15 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

16 hours ago