Cisco is warning about seven ClamAV vulnerabilities affecting its Secure Endpoint Connector products. Exploit code is already publicly available for two of the flaws.
ClamAV is an open-source, cross-platform malware detection engine that provides features including a multithreaded virtual scanner, email filtering, and automatic database updates. Tracked as CVE-2026-20337 through CVE-2026-20339 and CVE-2026-20345 through CVE-2026-20348, the vulnerabilities were identified in ClamAV parsers for the ZIP, GPT, PESpin, PDF, Mach-O, and XAR file formats. An unauthenticated remote attacker could exploit the flaws to cause a denial-of-service condition.
The vulnerabilities have already been fixed in ClamAV version 1.5.4. The release also addresses a path traversal vulnerability in WinRAR for Windows that could have allowed arbitrary code execution.
Shortly after the ClamAV fixes were released, Cisco issued its own security advisory warning that exploit code is already available for CVE-2026-20337 and CVE-2026-20338. No workarounds are available for any of the vulnerabilities. Cisco plans to release security updates for all affected Secure Endpoint Connector products during August.
Higher Risk on Windows
According to Cisco, the vulnerabilities pose a high risk to Windows users because the ClamAV scanning process runs with elevated privileges on that platform. On macOS and Linux, Cisco rates the risk as medium because the scanning process runs with fewer privileges.
The Secure Endpoint Private Cloud service itself is not affected by the vulnerabilities. However, the associated Secure Endpoint Connector software is vulnerable. Cisco recommends that customers deploy the available patches from the cloud to their endpoints. The fixes are included in Secure Endpoint Private Cloud versions 4.2.8 and later.
Cisco said it has so far found no evidence that the vulnerabilities are being exploited in the wild.
(Editorial Team)