Find notable cyber news and cases, enriched with sources, timelines, and signals.

Cisco security patch release for CVE-2026-20337

Security Patch Release
First reported
Last updated
Happening score
H score 30
1 unique sources, 1 articles

Summary

Hide ▲

Cisco released ClamAV 1.5.4 to fix CVE-2026-20337 and CVE-2026-20338, reducing denial-of-service risk for deployments running ClamAV 1.5.0 through 1.5.3. The update closes ZIP archive parser flaws that can let an unauthenticated attacker crash the scanning process by submitting a crafted zip file. Cisco said Secure Endpoint Connector updates for Windows, Linux, and Mac will follow later this month. The company also said there are no workarounds for the two bugs, although it has no evidence of in-the-wild exploitation.

Related Happenings

Cisco security patch release for CVE-2026-20303

Security Patch Release
H score43 First: 06.08.2026 20:13 Last: 06.08.2026 20:13 Sources 1

About this happening: Cisco rolled out updates for Cisco Catalyst SD-WAN Software to fix five critical CVEs across affected releases, including CVE-2026-20303 and CVE-2026-20304. Th...

Google’s Chrome security team security patch release for CVE-2026-17650

Security Patch Release
H score16 First: 30.07.2026 12:15 Last: 30.07.2026 12:15 Sources 1

About this happening: Google released Chrome 151 security patches for Windows, Mac, and Linux, fixing 370 vulnerabilities and seven critical issues. The update includes CVEs CVE-2026-...

Cisco Unified Communications Manager security update for CVE-2026-20230

Security Patch Release
H score56 First: 04.06.2026 14:09 Last: 04.06.2026 14:09 Sources 1

About this happening: Cisco released security updates for Cisco Unified Communications Manager (Unified CM) to fix CVE-2026-20230, a critical flaw that could let a remote attacker reach...

Cisco Secure Workload REST API patch release (CVE-2026-20223)

Security Patch Release
H score55 First: 22.05.2026 08:36 Last: 22.05.2026 08:36 Sources 1

About this happening: Cisco patched CVE-2026-20223, a CVSS 10.0 Secure Workload REST API flaw that could expose sensitive data and allow configuration changes across tenant boundaries. The upda...

Cisco ThousandEyes and Nexus security patches

Security Patch Release
H score31 First: 21.05.2026 15:04 Last: 21.05.2026 15:04 Sources 1

About this happening: Cisco released patches for three medium-severity vulnerabilities affecting ThousandEyes Virtual Appliance, ThousandEyes Enterprise Agent, and Nexus 3000/9000 switche...

Timeline

  1. 11.08.2026 14:03 2 articles · 1h ago

    Cisco security patch release for CVE-2026-20337

    Initial Disclosure

    Cisco released ClamAV 1.5.4 on August 7 to address two high-severity DoS flaws in the ZIP archive parser and announced later-month remediation for Secure Endpoint Connector on Windows, Linux, and Mac.

    Show sources