Cisco Warns ClamAV Vulnerabilities Have Public PoC Exploits

TL;DR. Cisco alerted users to high-severity denial-of-service vulnerabilities in its Secure Endpoint Connector ClamAV module, with public proof-of-concept code. - Seven flaws affect ClamAV's parsers for various file formats on Windows, macOS, and Linux systems. - Two specific vulnerabilities, CVE-2026-20337 and CVE-2026-20338, have known public exploits. - Patches are available in ClamAV version 1.5.4 and will roll out to Secure Endpoint Connector products in August.

Sources

Back to QLANKR News