Cisco Warns Windows Users of High-Severity ClamAV Flaws, Two With Working Attack Code Released
Seven vulnerabilities in the ClamAV antivirus engine affect Cisco's Secure Endpoint Connector software across Windows, macOS, and Linux. Patches land in August.

Key points - Seven vulnerabilities in ClamAV, the open-source antivirus engine built into Cisco's Secure Endpoint Connector, were publicly disclosed by Cisco on Friday. - CVE-2026-20337 and CVE-2026-20338 already have working proof-of-concept exploit code available, meaning criminals could use them as a starting point for attacks. - All seven bugs can cause a denial-of-service condition, where the scanning process crashes and stops working. - Windows users face the higher risk because ClamAV runs with administrator-level privileges on that platform. - Cisco says security updates for all affected Secure Endpoint Connector products will ship in August 2026.
Cisco has warned customers that seven security flaws in ClamAV, the open-source antivirus engine its Secure Endpoint Connector products rely on, could allow attackers to crash the scanning software entirely. Working exploit code for two of the flaws is already publicly available, as first reported by SecurityWeek. It's the latest in a run of Cisco vulnerability disclosures: we reported on a dozen flaws in SD-WAN and IOS XE on 6 August, three of them rated critical.
ClamAV (short for Clam AntiVirus) is a free, widely used malware-detection engine. Cisco bundles it inside its Secure Endpoint Connector software, which sits on company computers and servers to scan files for threats.
What exactly is the risk?
Every one of the seven bugs causes a denial-of-service condition: craft a malicious file, send it past a ClamAV scanner, and the scanner crashes. It stops working until restarted, leaving a gap where other malicious files could slip through undetected.
The flaws, tracked as CVE-2026-20337 through CVE-2026-20339 and CVE-2026-20345 through CVE-2026-20348, sit in the parsers ClamAV uses to inspect ZIP archives, GPT disk images, PESpin packed executables, PDF documents, Mach-O Mac application bundles, and XAR archives.
Cisco rates the risk as high on Windows, where ClamAV runs with full administrator privileges. On macOS and Linux, where the scanner runs with fewer system permissions, the rating drops to medium.
| CVE ID | Affected file parser | Severity on Windows |
|---|---|---|
| CVE-2026-20337 | ZIP | High (PoC public) |
| CVE-2026-20338 | GPT disk image | High (PoC public) |
| CVE-2026-20339 | PESpin packed executables | High |
| CVE-2026-20345 | High | |
| CVE-2026-20348 | (see advisory) | High |
Should Cisco customers act now?
Full patches for the Secure Endpoint Connector software itself aren't here yet. Cisco says updates will roll out in August. No workaround exists in the meantime.
Cisco reports no evidence of active exploitation. The public proof-of-concept code demonstrates the crashes but doesn't, on its own, break into a system. Fixes for the underlying ClamAV bugs are already in ClamAV version 1.5.4. Customers running Secure Endpoint Private Cloud can push those patches to connected endpoints from release 4.2.8 onwards. Secure Endpoint Private Cloud itself is not affected.
The practical concern here isn't a remote takeover. It's that a crashed scanner is a blind scanner, and an attacker who knows that can time a follow-on payload for exactly that window.
What affected organisations should do
Check whether you run Cisco Secure Endpoint Connector on Windows, macOS, or Linux machines. If you do, monitor Cisco's advisory page for the August update and apply it promptly. Prioritise Windows machines given the higher-privilege exposure, and watch ClamAV scan logs for unexpected crashes until patches arrive.



