Security News

Cybersecurity news aggregator

HIGH Vulnerabilities SC Media

Cisco warns of 7 ClamAV flaws impacting Secure Endpoint Connector

Cisco has disclosed seven vulnerabilities (CVE-2026-20337 through CVE-20339 and CVE-20345 through CVE-20348) in the ClamAV engine used by its Secure Endpoint Connector, where flaws in file format parsers, such as the zip archive parser, can lead to out-of-bounds writes, memory corruption, and denial-of-service conditions. Two of the CVEs have a CVSS score of 7.5 (HIGH), and while no active exploits are confirmed, the risk is highest for Windows due to elevated privileges. Cisco has stated patches are expected in August, and no workarounds are currently available.
Read Full Article →

Vulnerability Management Cisco warns of 7 ClamAV flaws impacting Secure Endpoint Connector August 12, 2026 Share By SC Staff Cisco has issued a warning regarding seven vulnerabilities discovered in the ClamAV antivirus engine, which affect its Secure Endpoint Connector products for Windows, macOS, and Linux. Two of these flaws have publicly available proof-of-concept exploits that could allow unauthenticated attackers to trigger denial-of-service conditions, according to a recent report by Security Affairs. The vulnerabilities, identified as CVE-2026-20337 through CVE-2026-20339 and CVE-2026-20345 to CVE-2026-20348, impact ClamAV's parsers for various file formats. Specifically, CVE-2026-20337 and CVE-2026-20338, both with a CVSS score of 7.5, relate to vulnerabilities in the zip archive parser. These could allow remote attackers to cause out-of-bounds writes or memory corruption, leading to the termination of ClamAV scanning operations. Cisco has stated that while there is no evidence of these vulnerabilities being exploited in the wild, patches are expected in August. The risk is considered high for Windows due to ClamAV running with elevated privileges, while macOS and Linux face a medium risk. No workarounds are currently available for these issues. Source: Security Affairs SC Staff Related Vulnerability Management Zoom vulnerabilities could enable RCE against meeting participants Laura French August 12, 2026 The flaws involving Zoom’s screenshare annotation feature were discovered with AI assistance. Vulnerability Management Microsoft SharePoint Server bug exploited in ransomware attacks Steve Zurier August 11, 2026 CISA gave no specifics, but one expert said it's potentially the work of China-linked Storm-2603. Vulnerability Management Progress LoadMaster bug added to CISA list of exploited vulnerabilities Steve Zurier August 10, 2026 CISA warns of active Progress LoadMaster attacks; patch and investigate now. Related Events Cybercast State of Vulnerability Management Thu Sep 10 Cybercast Why Mythos is the cybersecurity crisis we need On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Bug Buffer Overflow Disassembly You can skip this ad in 5 seconds

Share this article