Cisco Warns of Seven ClamAV Flaws, Two With Public PoCs
ID: ebc3cb1e-a888-5687-8ed4-52da47808c9f
STIX ID: report--ebc3cb1e-a888-5687-8ed4-52da47808c9f
Feed Name: Security Affairs
Threat Score
Cisco warns that seven vulnerabilities in the ClamAV engine used by its Secure Endpoint Connector (Windows, macOS, Linux) can allow remote denial-of-service conditions; two of the issues (CVE-2026-20337 and CVE-2026-20338) have public proof-of-concept code. ClamAV fixed the issues in version 1.5.4, Cisco plans patches for its products in August, reports no observed exploitation, and rates Windows impact as high due to elevated privileges while macOS/Linux are medium.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
