Cisco warns of high-severity ClamAV flaws with public exploits
A pair of high-severity vulnerabilities affecting ClamAV, a widely-used open-source antivirus engine, have been disclosed by Cisco. The flaws, which were found in the ZIP archive parser, can be exploited to crash the scanning process and deny service (DoS) attacks, and proof-of-concept exploit code is already publicly available. The two vulnerabilities, tracked as CVE-2026-20337 and … Read more