
Cisco warned that seven ClamAV vulnerabilities affect its Secure Endpoint Connector on Windows, macOS and Linux. ClamAV is an open-source antivirus engine widely used to scan files and emails for malware.
The company states that two flaws have public PoCs and could let unauthenticated attackers cause DoS conditions.
“Multiple vulnerabilities in ClamAV could allow a remote attacker to cause a denial of service (DoS) condition, interrupting scanning operations.” reads the advisory.
The flaws, tracked as CVE-2026-20337 to CVE-2026-20339 and CVE-2026-20345 to CVE-2026-20348, affect ClamAV parsers for several file formats. ClamAV fixed them in version 1.5.4, Cisco later warned that public PoCs are available for the vulnerabilities CVE-2026-20337 and CVE-2026-20338. Company’s PSIRT said it has no evidence that attackers have exploited these vulnerabilities in the wild.
“”The Cisco PSIRT is aware that proof-of-concept exploit code is available for the vulnerabilities that are described in CVE-2026-20337 and CVE-2026-20338.The Cisco PSIRT is not aware of proof-of-concept exploit code for any of the other vulnerabilities that are described in this advisory.” continues the advisory. “The Cisco PSIRT is not aware of any malicious use of the vulnerabilities that are described in this advisory.”
Below are the descriptions of CVE-2026-20337 and CVE-2026-20338:
Cisco identified the affected products in its advisory and recommends customers check the related bug IDs for details on each vulnerability.
| Affected Cisco Software Platform | CVSS Base Score | Security Impact Rating | Cisco Bug IDs | First Fixed Release |
|---|---|---|---|---|
| Secure Endpoint Connector for Linux | 5.3 | Medium | CSCwv87285 | Release no. TBD (Aug 2026) |
| Secure Endpoint Connector for Mac | 5.3 | Medium | CSCwv87286 | Release no. TBD (Aug 2026) |
| Secure Endpoint Connector for Windows | 7.5 | High | CSCwv87283 | Release no. TBD (Aug 2026) |
Secure Endpoint Private Cloud is not affected, but must distribute the fixes to endpoints.
Cisco said no workaround is available. Patches will be released in August. The flaws are high risk on Windows because ClamAV runs with elevated privileges, while macOS and Linux face medium risk.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, newsletter)