Cisco warned that its Secure Endpoint Connector products on Windows, macOS, and Linux are affected by seven ClamAV vulnerabilities that can cause denial-of-service conditions, with public proof-of-concept code available for two of them. The flaws were fixed in ClamAV 1.5.4, and Cisco says no exploitation in the wild is known so far, while updates will be rolled out in August. #Cisco #ClamAV #CVE-2026-20337 #CVE-2026-20338 #CVE-2026-20339 #CVE-2026-20345 #CVE-2026-20346 #CVE-2026-20347 #CVE-2026-20348
Keypoints
- Cisco Secure Endpoint Connector is affected on Windows, macOS, and Linux.
- Seven ClamAV flaws can trigger denial-of-service conditions.
- Two vulnerabilities, CVE-2026-20337 and CVE-2026-20338, have public PoC code.
- The bugs affect ZIP, GPT, PESpin, PDF, Mach-O, and XAR parsers.
- ClamAV 1.5.4 includes fixes, and Cisco plans to roll out updates in August.
Read More: https://www.securityweek.com/cisco-warns-of-high-severity-clamav-vulnerabilities-with-public-poc/