Cisco warns ClamAV flaws with public proof-of-concept code affect Secure Endpoint Connector

Cisco says seven vulnerabilities in the ClamAV antivirus engine affect its Secure Endpoint Connector software on Windows, macOS, and Linux, and could let remote attackers crash scanning processes. The bugs are tracked as CVE-2026-20337 to CVE-2026-20339 and CVE-2026-20345 to CVE-2026-20348, affect parsers for ZIP, GPT, PESpin, PDF, Mach-O, and XAR files, and were patched in ClamAV 1.5.4; Cisco said proof-of-concept exploit code exists for CVE-2026-20337 and CVE-2026-20338 and that fixes will roll out in August.
Why it matters: Organizations using Cisco Secure Endpoint Connector should treat this as a patching item now, especially on Windows where Cisco says the scanner runs with higher privileges. Even without known in-the-wild exploitation, public proof-of-concept code raises the risk of denial-of-service attacks via malicious files.

Sources

Cisco warns of high-severity ClamAV flaws with public exploits
Sergiu Gatlan 2026.08.11 97% relevant
This article appears to be the same underlying event and adds specifics on two newly assigned CVEs (CVE-2026-20337 and CVE-2026-20338), the affected ClamAV versions 1.5.0 through 1.5.3, patch version 1.5.4, the ZIP parser attack vector, and Cisco’s statement that Secure Endpoint Connector fixes are planned later this month.
Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC
Ionut Arghire 2026.08.10 100% relevant
This article establishes a distinct new story: Cisco's advisory that seven ClamAV CVEs, including two with public proof-of-concept code, affect Secure Endpoint Connector and require vendor updates.
← Back to all stories