logo

Cisco Warns of Seven ClamAV Flaws, Two With Public PoCs

ID: ebc3cb1e-a888-5687-8ed4-52da47808c9f

STIX ID: report--ebc3cb1e-a888-5687-8ed4-52da47808c9f

Feed Name: Security Affairs

Threat Score
55/100

Date Published: 2026-08-11

Date Updated: 2026-08-11

Author: Pierluigi Paganini

...
...

Cisco warns that seven vulnerabilities in the ClamAV engine used by its Secure Endpoint Connector (Windows, macOS, Linux) can allow remote denial-of-service conditions; two of the issues (CVE-2026-20337 and CVE-2026-20338) have public proof-of-concept code. ClamAV fixed the issues in version 1.5.4, Cisco plans patches for its products in August, reports no observed exploitation, and rates Windows impact as high due to elevated privileges while macOS/Linux are medium.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.