
CISCO has issued a warning about seven ClamAV vulnerabilities affecting its Secure Endpoint Connector for Windows, macOS and Linux that could allow unauthenticated remote attackers to crash the malware scanner and cause a denial of service.
The flaws are tracked as CVE-2026-20337, CVE-2026-20339, CVE-2026-20345, CVE-2026-20346, CVE-2026-20347 and CVE-2026-20348, each carrying a CVSS score of 7.5 (High) and being triggerable by submitting a specially crafted file to the scanner; two of the issues have public proof‑of‑concept code available.
The vulnerabilities impact ClamAV releases prior to version 1.5.4 and the corresponding Secure Endpoint Connectors, with the highest risk on Windows where the engine runs with elevated privileges, while macOS and Linux deployments face a moderate risk; Cisco notes that its Secure Endpoint Private Cloud offering is not affected and that patches are available in ClamAV 1.5.4 and in cloud releases 4.2.8 and later.
To date none of the flaws have been observed in the wild and no threat actors have been linked to them, but the availability of exploit code raises the likelihood of future attacks, especially against organisations that have not yet applied the updates.
Defenders should immediately apply the latest ClamAV engine update to all endpoints, push the corresponding connector patches from Cisco Secure Endpoint cloud release 4.2.8 or newer, and verify that the software version reports 1.5.4 or higher.
In addition, organisations should monitor endpoint logs for unexpected scanner terminations, restrict the acceptance of unsolicited files where feasible, and test the patches in a staging environment before broad deployment to ensure continued protection against malware.