Multiple ClamAV Vulnerabilities Allow Remote Attacker to Trigger DoS Condition
Brief
Cisco has disclosed multiple high-severity vulnerabilities in ClamAV that could allow unauthenticated remote attackers to disrupt antivirus scanning operations and cause denial-of-service conditions.
The flaws affect the ClamAV parsers used by Cisco Secure Endpoint Connector on Windows, Linux, and macOS. The advisory, tracked as cisco-sa-clamav-WuuvVd26, was first published on August 7, 2026, and updated on August 10.
Cisco assigned a High security impact rating to affected Windows systems, while Linux and macOS environments received a Medium rating. The company said the difference is due to the privileged security context used by the ClamAV scanning process on Windows devices.
Multiple ClamAV Vulnerabilities
The vulnerabilities include CVE-2026-20337, CVE-2026-20338, CVE-2026-20339, CVE-2026-20345, CVE-2026-20346, CVE-2026-20347, and CVE-2026-20348. Most carry a CVSS score of 7.
