INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
ClamAV Flaw Exploit via Public PoC
| 2026-08-11 16:05 CRITICAL HIGHExecutive Summary AI-generated
The Cisco Secure Endpoint Connector, a critical software product, has been compromised with seven ClamAV vulnerabilities that affect its operation on Windows, macOS, and Linux platforms. The flaws, identified as CVE-2026-20337 to CVE-2026-20348, have public proof-of-concept exploit code available for the vulnerabilities described in this advisory. Cisco warns of high risk on Windows due to elevated privileges while macOS and Linux face medium risk. The PSIRT has acknowledged that no malicious use is anticipated from these vulnerabilities.
Technical Mitigations AI-generated
* Implement a secure file format validation mechanism to detect and prevent zip files with crafted content that could exploit the ClamAV Zip File Format Processing Out-of-Bounds Write Vulnerability (CVE-2026-20337) or Memory Corruption Vulnerability (CVE-2026-20338).
* Regularly update and patch all systems, including operating systems, software applications, and network devices, to ensure timely application of security fixes for the identified vulnerabilities.
* Configure ClamAV to run with elevated privileges on Windows systems, which can help mitigate the high-severity risk associated with this vulnerability.
Technical Observables
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-20338CVE-2026-20338
CVE-2026-20337CVE-2026-20337
CVE-2026-20339CVE-2026-20339
CVE-2026-20345CVE-2026-20345
CVE-2026-20348CVE-2026-20348
Target & Sectors
Global Scope
Incident Timeline
November 2021
Threat actors used a Cisco vulnerability to target the Ransomware.
Click on any entity below to view its context and source!
tactic
Ransomware
Since November 2021, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has
tagged 95 Cisco vulnerabilities
as actively exploited in attacks, six of them abused in ransomware attacks.
general_metric
95 Cisco vulnerabilities
Since November 2021, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has
tagged 95 Cisco vulnerabilities
as actively exploited in attacks, six of them abused in ransomware attacks.
January 2025
Threat actors used a public proof-of-concept (PoC) exploit code to target ClamAV in January 2025.
Click on any entity below to view its context and source!
organisation
ClamAV DoS
It patched
another ClamAV DoS vulnerability
with PoC exploit code in January 2025, warning that attackers could abuse it to terminate the ClamAV antivirus scanner, preventing or delaying further scanning operations.
August 7
Threat actors exploited a vulnerability in ClamAV 1.5.0 through 1.5.3 by using publicly available proof of concept (PoC) versions of the software on August 7.
Click on any entity below to view its context and source!
infrastructure
1.5.4
"
These two vulnerabilities affect ClamAV 1.5.0 through 1.5.3, and they were patched in version 1.5.4
released on August 7
.
infrastructure
1.5.0
"
These two vulnerabilities affect ClamAV 1.5.0 through 1.5.3, and they were patched in version 1.5.4
released on August 7
.
infrastructure
1.5.3
"
These two vulnerabilities affect ClamAV 1.5.0 through 1.5.3, and they were patched in version 1.5.4
released on August 7
.
2026/08/11
Cisco warned of seven ClamAV flaws, including CVE-2026-20337 and CVE-2026-20338, which affect its Secure Endpoint Connector on Windows, macOS, and Linux.
Click on any entity below to view its context and source!
infrastructure
Windows
Cisco warned that seven ClamAV vulnerabilities affect its Secure Endpoint Connector on Windows, macOS and Linux.
"
Cisco added that the flaws' security impact is high only for Windows platforms since they're the only ones that "run the ClamAV scanning process in a privileged security context.
While there are no workarounds for CVE-2026-20337 and CVE-2026-20338, the company plans to release software updates later this month to address them in affected versions of Secure Endpoint Connector for Windows, Linux, and Mac.
infrastructure
Macos
Cisco warned that seven ClamAV vulnerabilities affect its Secure Endpoint Connector on Windows, macOS and Linux.
infrastructure
Linux
Cisco warned that seven ClamAV vulnerabilities affect its Secure Endpoint Connector on Windows, macOS and Linux.
While there are no workarounds for CVE-2026-20337 and CVE-2026-20338, the company plans to release software updates later this month to address them in affected versions of Secure Endpoint Connector for Windows, Linux, and Mac.
Affected Cisco Software Platform
CVSS Base Score
Security Impact Rating
Cisco Bug IDs
First Fixed Release
Secure Endpoint Connector for Linux
5.3
Medium
CSCwv87285
Release no. TBD (Aug 2026)
organisation
Secure Endpoint Connector on
Cisco warned that seven ClamAV vulnerabilities affect its Secure Endpoint Connector on Windows, macOS and Linux.
organisation
Secure Endpoint Connector for
While there are no workarounds for CVE-2026-20337 and CVE-2026-20338, the company plans to release software updates later this month to address them in affected versions of Secure Endpoint Connector for Windows, Linux, and Mac.
infrastructure
5.3
Affected Cisco Software Platform
CVSS Base Score
Security Impact Rating
Cisco Bug IDs
First Fixed Release
Secure Endpoint Connector for Linux
5.3
Medium
CSCwv87285
Release no. TBD (Aug 2026)
organisation
Affected Cisco
Affected Cisco Software Platform
CVSS Base Score
Security Impact Rating
Cisco Bug IDs
First Fixed Release
Secure Endpoint Connector for Linux
5.3
Medium
CSCwv87285
Release no. TBD (Aug 2026)
organisation
CVE-2026
The flaws, tracked as CVE-2026-20337 to CVE-2026-20339 and CVE-2026-20345 to CVE-2026-20348, affect ClamAV parsers for several file formats.
infrastructure
1.5.4
ClamAV fixed them in version
1.5.4
, Cisco later warned that public PoCs are available for the vulnerabilities CVE-2026-20337 and CVE-2026-20338.
infrastructure
20338 descriptions
Below are the descriptions of CVE-2026-20337 and CVE-2026-20338:
CVE-2026-20337
(CVSS score of 7.5) –
CVE-2026-20337:
organisation
ZIP
The security flaws (tracked as
CVE-2026-20337
and
CVE-2026-20338
) were found in the ZIP archive parser of ClamAV (Clam AntiVirus), the open-source and cross-platform engine used to scan files for malware.
organisation
ClamAV
Cisco Warns of Seven ClamAV Flaws, Two With Public PoCs
Cisco warns that seven ClamAV flaws affect Secure Endpoint Connector products, with two having public PoCs that could enable remote DoS attacks.
Cisco warns of high-severity ClamAV flaws with public exploits.
organisation
Secure Endpoint Connector
Cisco Warns of Seven ClamAV Flaws, Two With Public PoCs
Cisco warns that seven ClamAV flaws affect Secure Endpoint Connector products, with two having public PoCs that could enable remote DoS attacks.
organisation
DoS
Cisco Warns of Seven ClamAV Flaws, Two With Public PoCs
Cisco warns that seven ClamAV flaws affect Secure Endpoint Connector products, with two having public PoCs that could enable remote DoS attacks.
Cisco warned of two high-severity vulnerabilities affecting the Secure Endpoint Connector that allow threat actors to crash the ClamAV scanning process in denial-of-service (DoS) attacks.
organisation
the Secure Endpoint Connector
Cisco warned of two high-severity vulnerabilities affecting the Secure Endpoint Connector that allow threat actors to crash the ClamAV scanning process in denial-of-service (DoS) attacks.
organisation
The Cisco PSIRT
“The Cisco PSIRT is not aware of any malicious use of the vulnerabilities that are described in this advisory.”
organisation
Cisco
As Cisco explained in a Friday advisory, the two vulnerabilities are due to improper boundary checks and memory handling, respectively, and can be exploited by unauthenticated, remote attackers.
organisation
Product Security Incident Response Team
The company's Product Security Incident Response Team (PSIRT) added that proof-of-concept (PoC) exploit code is already publicly available, but said that it has no evidence the flaws have been exploited in the wild.
organisation
PoC
The company's Product Security Incident Response Team (PSIRT) added that proof-of-concept (PoC) exploit code is already publicly available, but said that it has no evidence the flaws have been exploited in the wild.
organisation
XAR
On Friday, Cisco patched five other ClamAV security flaws that can also be exploited to trigger denial-of-service conditions by submitting malicious XAR, Mach-O, PDF, GPT, and PESpin files for scanning.
organisation
PDF
On Friday, Cisco patched five other ClamAV security flaws that can also be exploited to trigger denial-of-service conditions by submitting malicious XAR, Mach-O, PDF, GPT, and PESpin files for scanning.
organisation
GPT
On Friday, Cisco patched five other ClamAV security flaws that can also be exploited to trigger denial-of-service conditions by submitting malicious XAR, Mach-O, PDF, GPT, and PESpin files for scanning.
organisation
The Blue Report 2026
The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
Aug 2026
Threat actors exploited a vulnerability in ClamAV on Windows to gain unauthorized access.
Click on any entity below to view its context and source!
infrastructure
Windows
Secure Endpoint Connector for Windows
7.5
High
CSCwv87283
Release no. TBD (Aug 2026)
The flaws are high risk on Windows because ClamAV runs with elevated privileges, while macOS and Linux face medium risk.
infrastructure
7.5
Secure Endpoint Connector for Windows
7.5
High
CSCwv87283
Release no. TBD (Aug 2026)
infrastructure
Macos
The flaws are high risk on Windows because ClamAV runs with elevated privileges, while macOS and Linux face medium risk.
infrastructure
Linux
The flaws are high risk on Windows because ClamAV runs with elevated privileges, while macOS and Linux face medium risk.
infrastructure
5.3
Secure Endpoint Connector for Mac
5.3
Medium
CSCwv87286
Release no. TBD (Aug 2026)
organisation
Secure Endpoint
Secure Endpoint Connector for Mac
5.3
Medium
CSCwv87286
Release no. TBD (Aug 2026)
organisation
Secure Endpoint Private Cloud
Secure Endpoint Private Cloud is not affected, but must distribute the fixes to endpoints.
Tactical Metrics
Metrics
infrastructure
Windows
Affected Product
Click for context!
Cisco warned that seven ClamAV vulnerabilities affect its Secure Endpoint Connector on Windows, macOS and Linux.
Secure Endpoint Connector for Windows
7.5
High
CSCwv87283
Release no. TBD (Aug 2026)
The flaws are high risk on Windows because ClamAV runs with elevated privileges, while macOS and Linux face medium risk.
"
Cisco added that the flaws' security impact is high only for Windows platforms since they're the only ones that "run the ClamAV scanning process in a privileged security context.
While there are no workarounds for CVE-2026-20337 and CVE-2026-20338, the company plans to release software updates later this month to address them in affected versions of Secure Endpoint Connector for Windows, Linux, and Mac.
Metrics
infrastructure
Macos
Affected Product
Cisco warned that seven ClamAV vulnerabilities affect its Secure Endpoint Connector on Windows, macOS and Linux.
The flaws are high risk on Windows because ClamAV runs with elevated privileges, while macOS and Linux face medium risk.
Metrics
infrastructure
Linux
Affected Product
Cisco warned that seven ClamAV vulnerabilities affect its Secure Endpoint Connector on Windows, macOS and Linux.
Affected Cisco Software Platform
CVSS Base Score
Security Impact Rating
Cisco Bug IDs
First Fixed Release
Secure Endpoint Connector for Linux
5.3
Medium
CSCwv87285
Release no. TBD (Aug 2026)
The flaws are high risk on Windows because ClamAV runs with elevated privileges, while macOS and Linux face medium risk.
While there are no workarounds for CVE-2026-20337 and CVE-2026-20338, the company plans to release software updates later this month to address them in affected versions of Secure Endpoint Connector for Windows, Linux, and Mac.
Metrics
infrastructure
1.5.4
Software Version
ClamAV fixed them in version
1.5.4
, Cisco later warned that public PoCs are available for the vulnerabilities CVE-2026-20337 and CVE-2026-20338.
"
These two vulnerabilities affect ClamAV 1.5.0 through 1.5.3, and they were patched in version 1.5.4
released on August 7
.
Metrics
infrastructure
20,338
Descriptions
Below are the descriptions of CVE-2026-20337 and CVE-2026-20338:
CVE-2026-20337
(CVSS score of 7.5) –
CVE-2026-20337:
Metrics
infrastructure
5.3
Software Version
Affected Cisco Software Platform
CVSS Base Score
Security Impact Rating
Cisco Bug IDs
First Fixed Release
Secure Endpoint Connector for Linux
5.3
Medium
CSCwv87285
Release no. TBD (Aug 2026)
Secure Endpoint Connector for Mac
5.3
Medium
CSCwv87286
Release no. TBD (Aug 2026)
Metrics
infrastructure
7.5
Software Version
Secure Endpoint Connector for Windows
7.5
High
CSCwv87283
Release no. TBD (Aug 2026)
Metrics
infrastructure
1.5.0
Software Version
"
These two vulnerabilities affect ClamAV 1.5.0 through 1.5.3, and they were patched in version 1.5.4
released on August 7
.
Metrics
infrastructure
1.5.3
Software Version
"
These two vulnerabilities affect ClamAV 1.5.0 through 1.5.3, and they were patched in version 1.5.4
released on August 7
.
Intelligence Sources
Security Affairs
2026-08-11
Cisco Warns of Seven ClamAV Flaws, Two With Public PoCs
Security Affairs
BleepingComputer
2026-08-11
Cisco warns of high-severity ClamAV flaws with public exploits
BleepingComputer
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-08-12T06:02
Comprehensive Tactical Telemetry
Highly Correlated Entities
20x
organisation
Identified Entity
Secure Endpoint Connector on
entity
5x
vulnerability
Exploited CVE
CVE-2026-20337
cve
5x
infrastructure
Software Version
1.5.4
version
4x
timeline
Temporal Reference
2026
date
3x
infrastructure
Affected Product
Windows
software
Contextual Telemetry
Context Block
11 METRICS
vulnerability
CVSS Score
8
score
infrastructure
Descriptions
20,338
descriptions
tactic
MITRE ATT&CK Technique
T1592.002 - Software
technique
general metric
Medium
5
medium
general metric
Cscwv87283 Release
8
cscwv87283 release
tactic
Cyber Operation Type
Ransomware
tactic
attribution
Attributing Entity
the U.S. Cybersecurity and Infrastructure Security Agency
authority
general metric
Cisco Vulnerabilities
95
cisco vulnerabilities
general metric
Cve-2026
20,338
cve-2026
general metric
Blue Report
2,026
blue report
general metric
Simulations
338,000,000
simulations
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.