Cisco warns of high-severity ClamAV flaws with public exploits

A pair of high-severity vulnerabilities affecting ClamAV, a widely-used open-source antivirus engine, have been disclosed by Cisco. The flaws, which were found in the ZIP archive parser, can be exploited to crash the scanning process and deny service (DoS) attacks, and proof-of-concept exploit code is already publicly available.

The two vulnerabilities, tracked as CVE-2026-20337 and CVE-2026-20338, were discovered by Cisco’s Product Security Incident Response Team (PSIRT). According to Cisco, an attacker could exploit these flaws by submitting a crafted zip file for scanning. If successful, the attack would cause the ClamAV scanning process to terminate, resulting in a denial-of-service condition on the affected software.

Cisco has emphasized that the security impact of these vulnerabilities is high only for Windows platforms, as they are the only ones running the ClamAV scanning process in a privileged security context. The flaws affect ClamAV 1.5.0 through 1.5.3, and were patched in version 1.5.4, which was released on August 7.

It’s worth noting that while proof-of-concept exploit code is publicly available for these vulnerabilities, Cisco has stated that it has no evidence of them being exploited in the wild. Nevertheless, the presence of public exploit code increases the likelihood of an attack occurring if the flaws are not patched promptly.

Cisco’s advisory also highlights five other ClamAV security flaws that were patched on Friday. These vulnerabilities can be exploited to trigger denial-of-service conditions by submitting malicious XAR, Mach-O, PDF, GPT, and PESpin files for scanning. This is not an isolated incident – Cisco patched another ClamAV DoS vulnerability in January 2025, warning of the potential for attackers to abuse it to terminate the antivirus scanner.

The fact that these vulnerabilities have been publicly disclosed raises concerns about their potential impact on organizations using ClamAV. With proof-of-concept exploit code already available, it’s essential for administrators to update their systems as soon as possible to avoid becoming a target for attackers.

For those affected by these vulnerabilities, Cisco plans to release software updates later this month to address them in affected versions of Secure Endpoint Connector for Windows, Linux, and Mac. It’s crucial for security teams to stay vigilant and ensure that all layers of defense are up-to-date to prevent potential attacks.

Ultimately, the presence of public exploit code serves as a reminder that vulnerabilities can be exploited if not addressed promptly. As such, it’s essential for organizations to prioritize patching and updating their systems regularly to maintain a strong security posture. By doing so, they can minimize the risk of falling victim to an attack and stay one step ahead of potential threats.


Source: Bleeping Computer — 2026-08-11