Cisco Discloses High-Severity ClamAV Vulnerabilities Allowing Remote DoS Attacks

Cisco Discloses High-Severity ClamAV Vulnerabilities Allowing Remote DoS Attacks

First seen 11 Aug 2026, 12:08 UTC GbhackersBleepingcomputergithub.comblog.clamav.net 88% similarity 70.5

Article Content

Browse articles
ThreatCluster

Cisco has identified seven high-severity vulnerabilities in ClamAV, tracked as CVE-2026-20337, CVE-2026-20338, CVE-2026-20339, CVE-2026-20345, CVE-2026-20346, CVE-2026-20347, and CVE-2026-20348. These flaws enable unauthenticated remote attackers to crash the ClamAV scanning process through specially crafted files, leading to denial-of-service (DoS) conditions. The vulnerabilities were disclosed on August 7, 2026, and have a maximum CVSS score of 7.5. Cisco confirmed that proof-of-concept exploit code is publicly available, although there is no evidence of active exploitation. The flaws primarily affect Windows platforms, where the ClamAV scanning process runs in a privileged context. Cisco has released patches for these vulnerabilities in version 1.5.4 of ClamAV. Security teams are advised to apply these updates to mitigate the risk of exploitation.

Key Points: • Seven high-severity vulnerabilities in ClamAV allow remote DoS attacks. • Proof-of-concept exploit code for the vulnerabilities is publicly available. • Patches have been released for affected ClamAV versions, primarily impacting Windows.

ThreatCluster AI How this analysis works

Timeline

2026-08-07
CVE-2026-20337 to CVE-2026-20348 published
Cisco disclosed seven high-severity vulnerabilities in ClamAV, allowing remote attackers to disrupt antivirus scanning.
Bleepingcomputer
2026-08-07
ClamAV version 1.5.4 released
Cisco released a patch for the identified vulnerabilities in ClamAV version 1.5.4 to address the security issues.
Bleepingcomputer
2026-08-07
CVE-2026-20338 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-07
CVE-2026-20339 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-07
CVE-2026-20345 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-07
CVE-2026-20347 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-07
CVE-2026-20346 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-11
Cisco warns of vulnerabilities
Cisco issued a warning regarding the high-severity vulnerabilities in ClamAV, emphasizing the risk of DoS attacks.
Gbhackers

Community

Browse all →

Tracked Entities in This Story