CISCO has issued a warning regarding seven vulnerabilities in ClamAV that affect its Secure Endpoint Connector across Windows, macOS, and Linux. Two of these vulnerabilities have public proof-of-concept (PoC) exploits that could allow unauthenticated attackers to initiate denial of service (DoS) attacks, interrupting scanning operations. The vulnerabilities, identified as CVE-2026-20337 to CVE-2026-20339 and CVE-2026-20345 to CVE-2026-20348, have been patched in ClamAV version 1.5.4.
Cisco has reported no known exploitation of these vulnerabilities in the wild. The highest risk is associated with Windows, where ClamAV operates with elevated privileges. Recommended action includes checking Cisco's advisory for details on affected products and vulnerability impressions.