At a glance:
-
Cisco has warned that seven vulnerabilities in the ClamAV malware scanning engine affect Cisco Secure Endpoint Connector deployments on Windows, Linux, and macOS.
-
Two of the vulnerabilities have public proof-of-concept code and can be triggered through specially crafted ZIP files, causing the ClamAV scanning process to terminate and interrupt malware scanning operations.
-
Cisco reports no known exploitation in the wild and has released guidance for affected customers, with software updates being made available during August 2026.
Threat summary
On August 7, 2026, Cisco published an advisory warning that multiple vulnerabilities in the ClamAV malware scanning engine affect Cisco Secure Endpoint Connector for Windows, Linux, and macOS.
The vulnerabilities are tracked as:
-
CVE-2026-20337
-
CVE-2026-20338
-
CVE-2026-20339
-
CVE-2026-20345
-
CVE-2026-20346
-
CVE-2026-20347
-
CVE-2026-20348
Cisco assigned a high-severity rating to affected Windows deployments and a medium rating to Linux and macOS deployments because of differences in the privileges used by the ClamAV scanning process.
ClamAV is an open-source malware detection engine used to inspect files, archives, email attachments, and other content for malicious activity. Cisco Secure Endpoint Connector incorporates ClamAV as part of its malware scanning functionality.
The vulnerabilities affect file parsers responsible for processing ZIP, GUID Partition Table (GPT), PESpin, Portable Document Format (PDF), Mach-O, and XAR file formats.
According to Cisco, a remote adversary can trigger the vulnerabilities by submitting specially crafted files for scanning. Successful exploitation causes the ClamAV scanning process to terminate, resulting in a denial-of-service (DoS) condition that interrupts malware scanning operations.
Cisco updated the advisory on August 10, 2026, highlighting the availability of public proof-of-concept (PoC) code for two of the vulnerabilities, CVE-2026-20337 and CVE-2026-20338.
Cisco states that both vulnerabilities can be exploited remotely without authentication when a vulnerable system scans a crafted ZIP archive. The PoCs demonstrate termination of the ClamAV scanning process and the interruption of malware scanning activity.
CVE-2026-20337 (CVSS: 7.5)
CVE-2026-20337 is an out-of-bounds write vulnerability in ClamAV's ZIP archive parser. The vulnerability results from improper boundary validation when processing ZIP file contents during scanning.
An unauthenticated remote adversary can submit a crafted ZIP archive for scanning and trigger termination of the ClamAV scanning process, resulting in a DoS condition. Public PoC code demonstrates the ability to crash the scanning process using a malicious ZIP file.
CVE-2026-20338 (CVSS: 7.5)
CVE-2026-20338 is a memory handling vulnerability in ClamAV's ZIP archive parser. Cisco states that a specially crafted ZIP file can terminate the ClamAV scanning process and trigger a DoS condition.
Public PoC code demonstrates the ability to disrupt scanning operations through malicious ZIP content.
Analysis
ClamAV version 1.5.4 contains fixes for all seven vulnerabilities. Cisco has indicated that updates addressing the vulnerabilities will be released for affected Secure Endpoint Connector platforms in August. Cisco states that no workarounds are available.
For organizations using Cisco Secure Endpoint Connector, remediation involves deploying Cisco-provided Secure Endpoint Connector updates. Organizations that operate standalone ClamAV installations outside of Cisco products can upgrade directly to ClamAV version 1.5.4 or later.
Organizations can review endpoint monitoring for unexpected ClamAV process terminations, confirm that malware scanning services remain operational, and prioritize systems that routinely process externally supplied files, including archives and email attachments.