High severity7.5NVD Advisory· Published Jul 1, 2026· Updated Jul 9, 2026
CVE-2026-20216
CVE-2026-20216
Description
A vulnerability in the InstallShield file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device.
This vulnerability is due to improper handling of temporary resources during file scanning. An attacker could exploit this vulnerability by submitting a crafted InstallShield file to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to terminate the ClamAV scanning process and temporarily consume available system resources, resulting in a DoS condition on the affected software.
Affected products
8cpe:2.3:a:cisco:secure_endpoint:*:*:*:*:*:linux:*:*+ 2 more
- cpe:2.3:a:cisco:secure_endpoint:*:*:*:*:*:linux:*:*range: <1.29.0
- cpe:2.3:a:cisco:secure_endpoint:*:*:*:*:*:macos:*:*range: <1.27.2
- cpe:2.3:a:cisco:secure_endpoint:*:*:*:*:*:windows:*:*range: <8.6.2
- osv-coords2 versionspkg:rpm/opensuse/clamav&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/clamav&distro=openSUSE%20Tumbleweed
< 1.5.3-160000.1.1+ 1 more
- (no CPE)range: < 1.5.3-160000.1.1
- (no CPE)range: < 1.5.3-1.1
Patches
Vulnerability mechanics
References
1News mentions
3- ⚡ Weekly Recap: Proxy Botnets, Browser Ransomware, AI Agent Tricks, Fake PoC Malware and MoreThe Hacker News · Jul 6, 2026
- New ClamAV security patch closes seven scanner bugs dating back two decadesHelp Net Security · Jul 5, 2026
- ClamAV: Six File Format Parser Flaws Disclosed Together, Patched in 1.5.3/1.4.5Vypr Intelligence · Jul 3, 2026