Cisco has disclosed multiple high-severity vulnerabilities in ClamAV that could allow unauthenticated remote attackers to disrupt antivirus scanning operations and cause denial-of-service conditions.
The flaws affect the ClamAV parsers used by Cisco Secure Endpoint Connector on Windows, Linux, and macOS. The advisory, tracked as cisco-sa-clamav-WuuvVd26, was first published on August 7, 2026, and updated on August 10.
Cisco assigned a High security impact rating to affected Windows systems, while Linux and macOS environments received a Medium rating. The company said the difference is due to the privileged security context used by the ClamAV scanning process on Windows devices.
Multiple ClamAV Vulnerabilities
The vulnerabilities include CVE-2026-20337, CVE-2026-20338, CVE-2026-20339, CVE-2026-20345, CVE-2026-20346, CVE-2026-20347, and CVE-2026-20348. Most carry a CVSS score of 7.5 and can be exploited remotely without authentication or user interaction.
Successful exploitation could terminate the ClamAV scanning process, interrupting malware detection and creating a denial-of-service condition.
CVE-2026-20337 is an out-of-bounds write vulnerability in ClamAV’s ZIP archive parser. An attacker could send a specially crafted ZIP file to a vulnerable system for scanning. Improper boundary validation could then cause the scanner process to crash.
CVE-2026-20338 also affects ZIP file processing but is caused by improper memory handling. A crafted archive could trigger a double-free condition, terminating the scanning engine.
Another issue, CVE-2026-20339, affects the PESpin file format parser. The flaw results from insufficient boundary checks, which could lead to an integer overflow during file scanning.
Cisco warned that this issue could cause a denial-of-service attack and may have broader effects due to memory corruption.
CVEVulnerabilityImpactCVE-2026-20337ZIP parser out-of-bounds writeDoS/crashCVE-2026-20338ZIP parser double-freeDoS/crashCVE-2026-20339PESpin parser integer overflowDoS / memory corruptionCVE-2026-20345GPT parser memory corruptionDoS / crashCVE-2026-20346PDF parser out-of-bounds readDoS / crashCVE-2026-20347Mach-O parser out-of-bounds readDoS / crashCVE-2026-20348XAR parser boundary flawDoS / crash
The remaining vulnerabilities affect GPT, PDF, Mach-O, and XAR file parsers. CVE-2026-20345 involves an improper endian conversion when processing GPT files, which may lead to an out-of-bounds buffer write.
CVE-2026-20346 and CVE-2026-20347 affect PDF and Mach-O processing, respectively, allowing out-of-bounds buffer reads. CVE-2026-20348 affects XAR archive handling and is caused by improper boundary checks.
All flaws can be triggered when ClamAV scans attacker-controlled files. This makes email attachments, downloaded archives, shared documents, and files submitted through web applications possible delivery paths, depending on how ClamAV is deployed.
Cisco said the vulnerabilities are independent, meaning exploitation of one flaw is not required to exploit another. Cisco Secure Endpoint Connector for Windows is the most impacted product because the scanner runs in a privileged context.
Secure Endpoint Connector for Linux and Mac are also affected, although their lower-privileged scanning process reduces the security impact.
Cisco Secure Endpoint Private Cloud is not directly vulnerable, but organizations must distribute updated connector software to protected endpoints. Cisco confirmed that no workarounds are available.
Customers should apply the fixed Cisco Secure Endpoint Connector releases through the Secure Endpoint portal when they become available.
Private Cloud customers should ensure they are running version 4.2.8 or later to receive updated connector software through normal content update processes.
Cisco PSIRT is aware of public proof-of-concept exploit code for CVE-2026-20337 and CVE-2026-20338. However, the company said it has not observed malicious exploitation of any of these vulnerabilities in the wild.
Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.
The post Multiple ClamAV Vulnerabilities Allow Remote Attacker to Trigger DoS Condition appeared first on Cyber Security News.



