Cisco Warns Windows Users of High-Severity ClamAV Flaws, Two With Working Attack Code Released

Seven vulnerabilities in the ClamAV antivirus engine affect Cisco's Secure Endpoint Connector software across Windows, macOS, and Linux. Patches land in August.

ThreatVectr Newsdesk· 3 min read
Full-frame photoreal editorial image of a dimly lit corporate server room with rows of blue-lit racks, a soft red warning glow pulsing from one rack indicating
Share

Key points

  • Seven vulnerabilities in ClamAV, the open-source antivirus engine built into Cisco's Secure Endpoint Connector, were publicly disclosed by Cisco on Friday.
  • Two flaws, CVE-2026-20337 and CVE-2026-20338, already have working proof-of-concept exploit code available, meaning criminals could use them as a starting point for attacks.
  • All seven bugs can cause a denial-of-service condition, where the scanning process crashes and stops working.
  • Windows users face the higher risk because ClamAV runs with administrator-level privileges on that platform.
  • Cisco says security updates for all affected Secure Endpoint Connector products will ship in August 2026.

Cisco has warned customers that seven security flaws in ClamAV, the open-source antivirus engine its Secure Endpoint Connector products rely on, could allow attackers to crash the scanning software entirely. The company confirmed that working exploit code for two of the flaws is already publicly available, as first reported by SecurityWeek.

ClamAV (short for Clam AntiVirus) is a free, widely used malware-detection engine. Cisco bundles it inside its Secure Endpoint Connector software, which sits on company computers and servers to scan files for threats.

What exactly is the risk?

All seven bugs cause a denial-of-service condition: an attacker can craft a malicious file that, when scanned by ClamAV, causes the scanner to crash. The antivirus stops working until restarted, leaving a window where other malicious files could slip through undetected.

The flaws, tracked as CVE-2026-20337 through CVE-2026-20339 and CVE-2026-20345 through CVE-2026-20348, sit in the parts of ClamAV that read and inspect common file formats including ZIP archives, PDF documents, and Mac application bundles (Mach-O files).

Cisco rates the risk as high on Windows, where ClamAV runs with full administrator privileges, meaning a crash there is more disruptive and potentially more dangerous. On macOS and Linux, where the scanner runs with fewer system permissions, Cisco rates the risk as medium severity.

CVE ID Affected file parser Severity on Windows
CVE-2026-20337 ZIP High (PoC public)
CVE-2026-20338 GPT disk image High (PoC public)
CVE-2026-20339 PESpin (packed executables) High
CVE-2026-20345 PDF High
CVE-2026-20346 Mach-O (Mac apps) High
CVE-2026-20347 XAR archive High

Should Cisco customers act now?

Full patches are not yet available for the Secure Endpoint Connector software itself. Cisco says updates will roll out in August. No workaround exists in the meantime.

The good news: Cisco says it has no evidence that any of these flaws are being actively exploited right now. The working exploit code that is public demonstrates the crashes but does not by itself break into a system.

Fixes for the underlying ClamAV bugs are already included in ClamAV version 1.5.4. Customers running Secure Endpoint Private Cloud can push those patches to connected endpoints from Secure Endpoint Private Cloud release 4.2.8 onwards. Secure Endpoint Private Cloud itself is not affected.

What affected organisations should do

Check whether you run Cisco Secure Endpoint Connector on any Windows, macOS, or Linux machines. If you do, monitor Cisco's advisory page for the August update and apply it as soon as it ships. Prioritise Windows machines given the higher-privilege exposure. Until patches arrive, watch your ClamAV scan logs for unexpected crashes, which could indicate someone testing these flaws against your systems.

© 2026 Threat Vectr