CISCO disclosed seven ClamAV vulnerabilities on August 7, 2026, that allow unauthenticated remote attackers to crash the scanner with crafted files, resulting in denial of service (DoS) and halting malware scanning. None of the vulnerabilities have been confirmed exploited in the wild, but they each carry a severity score of 7.5 (High). The vulnerabilities affect ClamAV versions prior to 1.5.4 and Cisco Secure Endpoint connectors for Windows, Linux, and Mac. No workarounds exist, so Cisco strongly recommends applying the latest security updates to mitigate these vulnerabilities.
Cisco patches seven ClamAV flaws that could halt malware scans
CyberSIXT Evidence Panel
Primary Source
sec.cloudapps.cisco.com
Article by CyberSIXT
Timeline Coverage
Swipe to explore timeline
-
Cisco patches seven ClamAV flaws that could halt malware scans
securityonline.info
-
Cisco Patches Catalyst Center File Read Flaw and Seven ClamAV DoS Bugs
securityonline.info