Skip to content
Cisco ClamAV Vulnerabilities Allow Remote DoS Attacks

Cisco ClamAV Vulnerabilities Allow Remote DoS Attacks

First seen 11 Aug 2026, 12:08 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •August 12, 2026 at 10:54 UTC
  • •Cisco disclosed seven high-severity vulnerabilities in ClamAV, allowing remote DoS attacks.
  • •Proof-of-concept exploit code is publicly available, raising the risk of exploitation.
  • •Patches have been released, but the Secure Endpoint Connector remains unpatched.

Cisco disclosed multiple high-severity vulnerabilities in ClamAV, tracked as CVE-2026-20337, CVE-2026-20338, CVE-2026-20339, CVE-2026-20345, CVE-2026-20346, CVE-2026-20347, and CVE-2026-20348. These flaws allow unauthenticated remote attackers to crash the antivirus scanning process via specially crafted ZIP and PDF files. The vulnerabilities were found in the ZIP archive parser and are particularly impactful on Windows systems. Proof-of-concept exploit code is publicly available, increasing the risk of imminent attacks. Cisco has released patches for the vulnerabilities, but a patched version of the Secure Endpoint Connector is still pending. Administrators are advised to apply the available security updates promptly to mitigate risks.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 56d ago How this analysis works

Timeline

2024-05-26
Public exploit for CVE-2025-8088 released
A proof-of-concept exploit appeared on GitHub, lowering the barrier for opportunistic attackers.
GitHub
2026-08-07
CVE-2026-20337, CVE-2026-20338 published
Cisco disclosed two high-severity vulnerabilities in ClamAV, allowing remote DoS attacks via crafted files.
Bleepingcomputer
2026-08-07
CVE-2026-20339, CVE-2026-20345, CVE-2026-20346, CVE-2026-20347, CVE-2026-20348 published
Cisco disclosed additional vulnerabilities in ClamAV, all allowing unauthenticated remote DoS attacks.
Gbhackers
2026-08-11
Patches released for ClamAV vulnerabilities
Cisco released patches for the disclosed vulnerabilities, urging administrators to apply them promptly.
Heise.De

More articles in this cluster (13)

Following this threat?

Track Cisco and CVE-2025-8088 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed