Find notable cyber news and cases, enriched with sources, timelines, and signals.

ClamAV ZIP archive parser DoS flaws (multiple vulnerabilities)

Vulnerability
First reported
Last updated
Happening score
H score 32
1 unique sources, 1 articles

Summary

Hide ▲

Cisco disclosed CVE-2026-20337 and CVE-2026-20338 in the ClamAV ZIP archive parser used by Secure Endpoint Connector. A crafted zip file can crash the scanning process and trigger a denial-of-service condition on affected systems. Cisco says public PoC exploit code is already available, but it has no evidence of in-the-wild exploitation. The flaws affect ClamAV 1.5.0 through 1.5.3 and are most serious on Windows because scanning runs in a privileged security context.

Timeline

  1. 11.08.2026 14:03 2 articles · 1h ago

    Cisco releases ClamAV 1.5.4 to fix CVE-2026-20337 and CVE-2026-20338

    Mitigation Patch Update

    Cisco released ClamAV 1.5.4 on August 7, 2026 to fix CVE-2026-20337 and CVE-2026-20338 in the ClamAV ZIP archive parser. The flaws affected ClamAV 1.5.0 through 1.5.3 and could let a remote unauthenticated attacker crash the ClamAV scanning process by submitting a crafted ZIP file.

    Show sources
  2. 11.08.2026 14:03 1 articles · 1h ago

    Cisco warns of ClamAV ZIP parser flaws with public exploit code

    Initial Disclosure

    Cisco warned that CVE-2026-20337 and CVE-2026-20338 in the ClamAV ZIP archive parser used by Secure Endpoint Connector can be exploited by unauthenticated remote attackers submitting a crafted ZIP file, causing the ClamAV scanning process to terminate in a denial-of-service condition. Cisco also said proof-of-concept exploit code is publicly available and that it has no evidence the flaws have been exploited in the wild.

    Show sources