Cisco warns of high-severity ClamAV flaws with public exploits

Cisco has issued a warning about two high-severity vulnerabilities affecting ClamAV, an open-source antivirus engine widely used to scan files for malware. The flaws allow unauthenticated attackers to crash the ClamAV scanning process in denial-of-service (DoS) attacks, and proof-of-concept exploit code is already publicly available.

The security issues were discovered in the ZIP archive parser of ClamAV, specifically in versions 1.5.0 through 1.5.3. According to Cisco’s advisory, an attacker could submit a crafted zip file for scanning, which would cause the ClamAV process to terminate and result in a DoS condition on affected software. This is particularly concerning because it can be exploited by unauthenticated, remote attackers.

The vulnerabilities, tracked as CVE-2026-20337 and CVE-2026-20338, are due to improper boundary checks and memory handling, respectively. While Cisco has no evidence that these flaws have been exploited in the wild, the fact that proof-of-concept exploit code is available makes it a high-risk threat. What’s more concerning is that this vulnerability affects Windows platforms specifically because they run the ClamAV scanning process in a privileged security context.

ClamAV 1.5.4 was released on August 7 with patches for these two vulnerabilities, as well as five other security flaws that can also be exploited to trigger denial-of-service conditions by submitting malicious files for scanning. Cisco plans to release software updates later this month to address the affected versions of Secure Endpoint Connector for Windows, Linux, and Mac.

This incident highlights the importance of keeping your antivirus software up-to-date, particularly if you’re using ClamAV. Regularly updating your security software can help prevent these types of attacks from succeeding. Additionally, it’s essential to monitor your systems for signs of malicious activity and have a robust incident response plan in place in case an attack does occur.

For those who use Secure Endpoint Connector on Windows, Linux, or Mac, be sure to check the Cisco website regularly for updates and patch them as soon as they’re available. If you’re not using ClamAV, consider exploring other antivirus options that have a more robust security record. In any case, stay vigilant and keep your systems updated – it’s always better to err on the side of caution when it comes to cybersecurity.


Source: Bleeping Computer — 2026-08-11