www.securityweek.com 8/10/2026, 2:41:57 PM · external

Cisco flags ClamAV bugs in Secure Endpoint Connector, risking DoS

Cisco flags ClamAV bugs in Secure Endpoint Connector, risking DoS
Developing story vulnerability 2 articles tracked
Cisco patches multiple ClamAV vulnerabilities that enable remote denial-of-service

CISCO has issued a warning regarding vulnerabilities in its Secure Endpoint Connector products for Windows, macOS, and Linux, stemming from seven ClamAV vulnerabilities. These vulnerabilities, identified as CVE-2026-20337 to CVE-2026-20339 and CVE-2026-20345 to CVE-2026-20348, could lead to denial-of-service (DoS) conditions, with two having public proof-of-concept (PoC) code available. Although patches are included in ClamAV version 1.5.4, no workarounds exist.

The risks are highest for Windows users due to the privileged context in which ClamAV operates, while the risk is moderate for macOS and Linux due to lower privilege levels. Users of Secure Endpoint Private Cloud are unaffected and are advised to push available patches from cloud releases 4.2.8 and later to their endpoints.

View Primary Source Via www.securityweek.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline