CVE-2026-20214Patch(cisco / clamav)

LOWCVSS 7.5 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch cisco clamav systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability in the FSG file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in FSG files during scanning, which may result in an out-of-bounds buffer write. An attacker could exploit this vulnerability by submitting a crafted file that contains portable executable content compressed with FSG to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-120

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • clamav
  • secure_endpoint

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • General: 2 classified signals
  • Peaked at 3 mentions on most recent observed day (2026-07-09)
  • 4 total mentions across 2 days

Affected systems

Products
clamavsecure_endpoint

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-07-02: 1Mentions · 2026-07-09: 3Patch / Workaround · 2026-07-02: 1Patch / Workaround · 2026-07-09: 1Technical Details · 2026-07-02: 1Technical Details · 2026-07-09: 207-0207-09
Signal classification2 categories
Patch
250.0%
General
250.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-07-021
Patch1
2026-07-093
General2Patch1
Full discourse4 posts
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos Cisco ❗ CVE-2026-20217 ❗ CVE-2026-20214 ❗ CVE-2026-20191 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-cisco-16/ https://t.co/AkC1AAqziU

    Post summary

    The post lists three Cisco CVEs and links to additional resources, but supplies no technical, exploit, patch, or active‑exploitation details.

    00000264
    6.7K followersView on X
  • ゆぅさん@YY20424277
    General

    【3軸解説】「シスコシステムズのCisco Secure Endpointにおける古典的バッファオーバーフローの脆弱性(CVE-2026-20214)」を、背景 / 目的 / 効果 の 3 軸で読み解きます。 背景/目的/効果の3軸で読み解きました。 #セキュリティ #若手コンサル ▶ 無料ツール WR-Analysis: https://www.intect-i.jp/tools/wr-analysis/?utm_source=sns&utm_medium=social&utm_campaign=wr_analysis

    Post summary

    The post provides a high‑level analysis of CVE‑2026‑20214, noting its buffer overflow nature, but no PoC, exploit code, active exploitation, or patch information is shared.

    0000080
    841 followersView on X
  • iototsecnews@iototsecnews
    Patch

    ClamAV の脆弱性 CVE-2026-20213/20214/20215 が FIX:サービス拒否 (DoS) の可能性 https://iototsecnews.jp/2026/07/02/multiple-clamav-vulnerabilities-allow-remote-attacker-to-cause-a-dos-condition/ セキュリティの要となる ClamAV において、 検査対象のデータを解析する内部処理の不備を原因とした深刻な問題が明らかになりました。この脆弱性 CVE-2026-20213/CVE-2026-20214/CVE-2026-20215 が悪用されると、 悪意のファイルを読み込む際に保護システムが突然停止してしまう恐れがあります。特定の環境では端末自体が応答しなくなるなど、防衛体制に大きな穴が空くリスクを伴います。安全な運用を維持するための対応策として、開発元から配布されている最新のコネクタへの更新を早期に適用し、常に最新の防御状態を保つように心がけてください。 #Cisco #ClamAV #CVE202620213 #CVE202620214 #CVE202620215 #Vulnerability

    Post summary

    The post reports that ClamAV suffered DoS‑capable flaws (CVE‑2026‑20213/24/15) and advises users to apply the vendor’s latest connector update to mitigate the risk; no evidence of active exploitation or POCs is provided.

    00000120
    500 followersView on X
  • TECHEPAGES@techepages
    Patch

    🚨 Cisco warns of multiple high-severity ClamAV flaws (advisory cisco-sa-clamav-88cFYyxR) letting remote attackers crash the AV engine via malformed files. Key CVEs: - CVE-2026-20216 - CVE-2026-20213 - CVE-2026-20214 - CVE-2026-20215 - CVE-2026-20217 - CVE-2026-20243 - CVE-2026-20244 These vulnerabilities are fixed in ClamAV 1.5.3 / 1.4.5. Cisco Security 📁 Windows hit hardest (CVSS 7.5), endpoints may need a reboot. No workarounds; patch Secure Endpoint Connector now.

    Post summary

    Cisco highlights multiple high‑severity ClamAV vulnerabilities that allow remote attackers to crash the AV engine via malformed files; users should apply the patch to ClamAV 1.5.3/1.4.5 and reboot endpoints as recommended.

    0000063
    22 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Appciscosecure_endpoint-linux-
Appciscosecure_endpoint-macos-
Appciscosecure_endpoint-windows-
Appclamavclamav---

Explore more