INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

ClamAV Flaw Exploit via Public PoC

| 2026-08-11 16:05 CRITICAL HIGH
Executive Summary AI-generated
The Cisco Secure Endpoint Connector, a critical software product, has been compromised with seven ClamAV vulnerabilities that affect its operation on Windows, macOS, and Linux platforms. The flaws, identified as CVE-2026-20337 to CVE-2026-20348, have public proof-of-concept exploit code available for the vulnerabilities described in this advisory. Cisco warns of high risk on Windows due to elevated privileges while macOS and Linux face medium risk. The PSIRT has acknowledged that no malicious use is anticipated from these vulnerabilities.
Technical Mitigations AI-generated
* Implement a secure file format validation mechanism to detect and prevent zip files with crafted content that could exploit the ClamAV Zip File Format Processing Out-of-Bounds Write Vulnerability (CVE-2026-20337) or Memory Corruption Vulnerability (CVE-2026-20338). * Regularly update and patch all systems, including operating systems, software applications, and network devices, to ensure timely application of security fixes for the identified vulnerabilities. * Configure ClamAV to run with elevated privileges on Windows systems, which can help mitigate the high-severity risk associated with this vulnerability.
Technical Observables
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-20338CVE-2026-20338 CVE-2026-20337CVE-2026-20337 CVE-2026-20339CVE-2026-20339 CVE-2026-20345CVE-2026-20345 CVE-2026-20348CVE-2026-20348
Target & Sectors
Global Scope
Incident Timeline
‎November 2021
Threat actors used a Cisco vulnerability to target the Ransomware.
tactic Ransomware
general_metric 95 Cisco vulnerabilities
‎January 2025
Threat actors used a public proof-of-concept (PoC) exploit code to target ClamAV in January 2025.
organisation ClamAV DoS
‎August 7
Threat actors exploited a vulnerability in ClamAV 1.5.0 through 1.5.3 by using publicly available proof of concept (PoC) versions of the software on August 7.
infrastructure 1.5.4
infrastructure 1.5.0
infrastructure 1.5.3
‎2026/08/11
Cisco warned of seven ClamAV flaws, including CVE-2026-20337 and CVE-2026-20338, which affect its Secure Endpoint Connector on Windows, macOS, and Linux.
infrastructure Windows
infrastructure Macos
infrastructure Linux
organisation Secure Endpoint Connector on
organisation Secure Endpoint Connector for
infrastructure 5.3
organisation Affected Cisco
organisation CVE-2026
infrastructure 1.5.4
infrastructure 20338 descriptions
organisation ZIP
organisation ClamAV
organisation Secure Endpoint Connector
organisation DoS
organisation the Secure Endpoint Connector
organisation The Cisco PSIRT
organisation Cisco
organisation Product Security Incident Response Team
organisation PoC
organisation XAR
organisation PDF
organisation GPT
organisation The Blue Report 2026
‎Aug 2026
Threat actors exploited a vulnerability in ClamAV on Windows to gain unauthorized access.
infrastructure Windows
infrastructure 7.5
infrastructure Macos
infrastructure Linux
infrastructure 5.3
organisation Secure Endpoint
organisation Secure Endpoint Private Cloud
Tactical Metrics
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
‎Macos
Affected Product
Metrics
infrastructure
‎Linux
Affected Product
Metrics
infrastructure
‎1.5.4
Software Version
Metrics
infrastructure
20,338
Descriptions
Metrics
infrastructure
‎5.3
Software Version
Metrics
infrastructure
‎7.5
Software Version
Metrics
infrastructure
‎1.5.0
Software Version
Metrics
infrastructure
‎1.5.3
Software Version
Intelligence Sources
Security Affairs 2026-08-11
BleepingComputer 2026-08-11