Feeds.4Sysops Cisco Patches Long-Standing Vulnerabilities in ClamAV Antivirus Engine
Article Content
- •Cisco patched seven vulnerabilities in ClamAV, versions 1.5.3 and 1.4.5.
- •Some vulnerabilities have existed for nearly two decades, posing long-term risks.
- •Organizations using ClamAV in various security tools are advised to apply the updates immediately.
Cisco's Talos group released security patches for ClamAV, an open-source antivirus engine, addressing seven vulnerabilities in versions 1.5.3 and 1.4.5. These flaws, some dating back nearly two decades, primarily affect the code responsible for unpacking and parsing executable formats. Organizations using ClamAV in mail gateways, file upload checks, and endpoint security tools are impacted. The vulnerabilities highlight risks associated with legacy parsing logic. The patches include fixes for critical issues that could potentially be exploited if left unaddressed. Security professionals are advised to update their systems promptly to mitigate risks. The vulnerabilities were confirmed by Cisco's Talos team and are now patched.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Continue Reading
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on…
Critical Citrix NetScaler Vulnerabilities Actively Exploited in Finland The National Cyber Security Centre Finland (NCSC-FI) issued an alert regarding critical vulnerabilities in Citrix NetScaler ADC and Gateway products, specifically CVE-2026-88771 and CVE-2026-88772, which are being actively exploited in Finland. These vulnerabilities allow attackers to execute remote code without…