Cisco says seven vulnerabilities in the ClamAV antivirus engine affect its Secure Endpoint Connector software on Windows, macOS, and Linux, and could let remote attackers crash scanning processes. The bugs are tracked as CVE-2026-20337 to CVE-2026-20339 and CVE-2026-20345 to CVE-2026-20348, affect parsers for ZIP, GPT, PESpin, PDF, Mach-O, and XAR files, and were patched in ClamAV 1.5.4; Cisco said proof-of-concept exploit code exists for CVE-2026-20337 and CVE-2026-20338 and that fixes will roll out in August.
Why it matters: Organizations using Cisco Secure Endpoint Connector should treat this as a patching item now, especially on Windows where Cisco says the scanner runs with higher privileges. Even without known in-the-wild exploitation, public proof-of-concept code raises the risk of denial-of-service attacks via malicious files.
Sergiu Gatlan
2026.08.11
97% relevant
This article appears to be the same underlying event and adds specifics on two newly assigned CVEs (CVE-2026-20337 and CVE-2026-20338), the affected ClamAV versions 1.5.0 through 1.5.3, patch version 1.5.4, the ZIP parser attack vector, and Cisco’s statement that Secure Endpoint Connector fixes are planned later this month.
Ionut Arghire
2026.08.10
100% relevant
This article establishes a distinct new story: Cisco's advisory that seven ClamAV CVEs, including two with public proof-of-concept code, affect Secure Endpoint Connector and require vendor updates.
← Back to all stories