Bleepingcomputer
Cisco Discloses High-Severity ClamAV Vulnerabilities Allowing Remote DoS Attacks
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Cisco has identified seven high-severity vulnerabilities in ClamAV, tracked as CVE-2026-20337, CVE-2026-20338, CVE-2026-20339, CVE-2026-20345, CVE-2026-20346, CVE-2026-20347, and CVE-2026-20348. These flaws enable unauthenticated remote attackers to crash the ClamAV scanning process through specially crafted files, leading to denial-of-service (DoS) conditions. The vulnerabilities were disclosed on August 7, 2026, and have a maximum CVSS score of 7.5. Cisco confirmed that proof-of-concept exploit code is publicly available, although there is no evidence of active exploitation. The flaws primarily affect Windows platforms, where the ClamAV scanning process runs in a privileged context. Cisco has released patches for these vulnerabilities in version 1.5.4 of ClamAV. Security teams are advised to apply these updates to mitigate the risk of exploitation.
Key Points: • Seven high-severity vulnerabilities in ClamAV allow remote DoS attacks. • Proof-of-concept exploit code for the vulnerabilities is publicly available. • Patches have been released for affected ClamAV versions, primarily impacting Windows.