Cisco warns of seven ClamAV flaws; two have PoC
Cisco warned seven ClamAV vulnerabilities in its Secure Endpoint Connector for Windows, macOS and Linux could cause denial-of-service; two have public proof-of-concept code. Fixes due in August.
Cisco warned that seven vulnerabilities in the ClamAV scanning engine used by its Secure Endpoint Connector on Windows, macOS and Linux could cause denial-of-service (DoS) conditions. Two of the flaws have publicly available proof-of-concept (PoC) code.
The defects are tracked as CVE-2026-20337 through CVE-2026-20339 and CVE-2026-20345 through CVE-2026-20348. They were found in ClamAV’s file-format parsers for ZIP, GPT, PESpin, PDF, Mach-O and XAR files. ClamAV is an open-source malware detection engine that provides multi-threaded scanning, email filtering and automatic database updates. ClamAV released fixes for the parsing bugs in version 1.5.4. That release also patched a WinRAR path traversal flaw on Windows that could allow arbitrary code execution.
Proof-of-concept exploit code is available for CVE-2026-20337 and CVE-2026-20338. The advisory notes the vulnerabilities pose higher risk on Windows because the ClamAV scanning process runs with elevated privileges there. On macOS and Linux, where the scanner runs with lower privileges, the issues are rated medium severity. Cisco reports no known exploitation of these flaws in the wild.
No temporary workaround is available for affected customers. Cisco plans to distribute security updates for all Secure Endpoint Connector products in August. Secure Endpoint Private Cloud is not exposed to these Connector-specific flaws; Private Cloud releases beginning with 4.2.8 include the ClamAV fixes. Administrators can push those cloud updates to endpoints to apply the fixes.
Administrators of Windows, macOS and Linux endpoints running Cisco’s Secure Endpoint Connector should prepare to apply the August updates as soon as they are available to address the DoS risk and mitigate exposure where PoC code exists.








