Skip to content
Security vulnerabilities: Attackers can disrupt ClamAV's watch service

Security vulnerabilities: Attackers can disrupt ClamAV's watch service

Heise.De August 11, 2026

Attackers can attack systems with ClamAV and disable the virus scanner in most cases. In two patched versions, the developers have now closed eight security vulnerabilities.

As indicated by the security section of the ClamAV website , in seven cases, attackers can trigger DoS states and thus scanner crashes after successful attacks. Since ClamAV typically runs on mail servers and gateways, a failure of virus protection can have fatal consequences.

Attacks are possible remotely and without authentication. Consequently, the DoS vulnerabilities are classified with the threat level “ high ”. To trigger such a state, attackers must, for example, submit prepared Zip archives or PDF files to the scanner for examination. Errors then occur during processing, leading to crashes (e.g., CVE-2026-20338).

On Windows, malicious code execution can even occur during the processing of RAR archives (CVE-2025-8088 “ high ”). After that, computers are generally considered to be fully compromised.

So far, network equipment manufacturer Cisco, to which ClamAV organizationally belongs, has not indicated that attackers are already exploiting the security vulnerabilities. However, proof-of-concept code is already in circulation for two vulnerabilities (CVE-2026-20337, CVE-2026-20338) , so attacks may be imminent. Accordingly, administrators should install the available security patches promptly.

The developers assure that the problems have been resolved in versions 1.4.6 and 1.5.4 . Cisco's Secure Endpoint Connector security solution uses ClamAV. However, a patched version is not yet available. According to the developers, it should follow this month.

This article was originally published in German . It was translated with technical assistance and editorially reviewed before publication.

Extracted Entities

Attack Types (1)

Domains (1)

Platforms (1)