Skip to content
Critical Vulnerabilities in ClamAV Affecting Multiple File Parsers

Critical Vulnerabilities in ClamAV Affecting Multiple File Parsers

First seen 15 Sep 2026, 10:53 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 15, 2026 at 11:56 UTC
  • Multiple critical vulnerabilities in ClamAV allow remote denial of service attacks.
  • Affected file parsers include PE, ZIP, and others, impacting various systems.
  • Immediate updates are necessary to prevent exploitation.

SUSE has issued important security advisories for ClamAV, addressing multiple denial of service vulnerabilities. The vulnerabilities, identified as CVE-2026-20213 through CVE-2026-20217 and CVE-2026-20337 through CVE-2026-20347, allow unauthenticated remote attackers to exploit flaws in various file format parsers, including PE, FSG, 7z, InstallShield, and ZIP. The affected systems include ClamAV versions prior to the latest updates. Attackers can gain admin control through chained exploits, raising significant security concerns. The vulnerabilities were published between July and August 2026, with some having proof-of-concept code available. Administrators are urged to update their ClamAV installations immediately to mitigate risks. The current status indicates that these vulnerabilities are actively being exploited.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2025-08-08
CVE-2025-8088 published
A critical vulnerability in ClamAV was disclosed, allowing potential exploitation.
Linuxsecurity
2026-07-01
Multiple CVEs published
CVE-2026-20213 to CVE-2026-20217 were published, addressing various file format parsers.
Linuxsecurity
2026-07-01
CVE-2026-20214 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-01
CVE-2026-20217 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-01
CVE-2026-20243 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-01
CVE-2026-20213 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-01
CVE-2026-20216 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-01
CVE-2026-20215 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-07
Additional CVEs published
CVE-2026-20337 to CVE-2026-20347 were published, focusing on ZIP and other file parsers.
Linuxsecurity
2026-08-07
CVE-2026-20337 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE

More articles in this cluster (3)

Following this threat?

Track SuSE and CVE-2025-8088 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed