ClamAV ZIP archive parser DoS flaws (multiple vulnerabilities)
Vulnerability
Summary
Hide ▲
Show ▼
Cisco disclosed CVE-2026-20337 and CVE-2026-20338 in the ClamAV ZIP archive parser used by Secure Endpoint Connector. A crafted zip file can crash the scanning process and trigger a denial-of-service condition on affected systems. Cisco says public PoC exploit code is already available, but it has no evidence of in-the-wild exploitation. The flaws affect ClamAV 1.5.0 through 1.5.3 and are most serious on Windows because scanning runs in a privileged security context.
Timeline
-
11.08.2026 14:03 2 articles · 1h ago
Cisco releases ClamAV 1.5.4 to fix CVE-2026-20337 and CVE-2026-20338
Mitigation Patch UpdateCisco released ClamAV 1.5.4 on August 7, 2026 to fix CVE-2026-20337 and CVE-2026-20338 in the ClamAV ZIP archive parser. The flaws affected ClamAV 1.5.0 through 1.5.3 and could let a remote unauthenticated attacker crash the ClamAV scanning process by submitting a crafted ZIP file.
Show sources
- Cisco warns of high-severity ClamAV flaws with public exploits — www.bleepingcomputer.com — 11.08.2026 14:03
- Cisco warns of high-severity ClamAV flaws with public exploits — www.bleepingcomputer.com — 11.08.2026 14:03
-
11.08.2026 14:03 1 articles · 1h ago
Cisco warns of ClamAV ZIP parser flaws with public exploit code
Initial DisclosureCisco warned that CVE-2026-20337 and CVE-2026-20338 in the ClamAV ZIP archive parser used by Secure Endpoint Connector can be exploited by unauthenticated remote attackers submitting a crafted ZIP file, causing the ClamAV scanning process to terminate in a denial-of-service condition. Cisco also said proof-of-concept exploit code is publicly available and that it has no evidence the flaws have been exploited in the wild.
Show sources
- Cisco warns of high-severity ClamAV flaws with public exploits — www.bleepingcomputer.com — 11.08.2026 14:03