Cisco Warns of High-Severity ClamAV Vulnerabilities With Public Proof-of-Concept
Cisco Talos has disclosed seven high-severity vulnerabilities in the ClamAV antivirus engine, with two flaws having publicly available proof-of-concept code, increasing the risk of denial-of-service attacks.

Cisco Talos has issued a critical warning regarding seven vulnerabilities discovered within the ClamAV antivirus engine, a widely used open-source cross-platform malware detection solution. These flaws, collectively tracked as CVE-2026-20337 through CVE-2026-20339 and CVE-2026-20345 through CVE-2026-20348, reside within ClamAV's parsers for various file formats including ZIP, GPT, PESpin, PDF, Mach-O, and XAR.
The most concerning aspect of this disclosure is the existence of publicly available proof-of-concept (PoC) code for two of these vulnerabilities, CVE-2026-20337 and CVE-2026-20338. This readily available exploit code significantly lowers the barrier to entry for malicious actors, making widespread exploitation a more immediate threat.
Exploiting these vulnerabilities can lead to denial-of-service (DoS) conditions, effectively rendering the affected systems unable to perform their security scanning functions. Cisco's Secure Endpoint Connector products on Windows, macOS, and Linux are all impacted. The severity of the risk varies by operating system; Windows users face a high risk due to the ClamAV scanning process running with privileged security context. On macOS and Linux, the risk is considered medium as the scanning process operates with lower privileges.
While ClamAV has released version 1.5.4 containing patches for these vulnerabilities, Cisco advises customers using their Secure Endpoint Connector products to apply the available security updates. These patches are included in Secure Endpoint Private Cloud releases 4.2.8 and later. Cisco has stated that no workaround currently exists for these specific vulnerabilities, emphasizing the importance of timely patching.
Cisco's Secure Endpoint Private Cloud itself is not affected by these particular flaws. However, the Secure Endpoint Connector software is vulnerable, and administrators are urged to push the necessary patches from the cloud to their endpoints to mitigate the risk.
Despite the public availability of PoC code, Cisco has indicated that they are not aware of any of these ClamAV vulnerabilities being actively exploited in the wild at the time of their advisory. However, the presence of public exploits often precedes widespread in-the-wild attacks, making proactive patching crucial.
The disclosure highlights the ongoing challenges in securing widely deployed open-source components. ClamAV's integration into numerous security products means that vulnerabilities within its engine can have a broad impact across different vendor ecosystems. The timely patching by ClamAV and subsequent advisories from vendors like Cisco are critical steps in defending against potential exploitation.
Organizations relying on ClamAV for their security infrastructure should prioritize the application of version 1.5.4 or later, and ensure their endpoint security solutions are updated accordingly. The availability of public exploits serves as a stark reminder of the need for rapid vulnerability management and patching cycles in today's threat landscape.