CVE-2026-20215Disclosure(cisco / clamav)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch cisco clamav systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability in the 7z file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in 7z files during scanning, which may result in an out-of-bounds buffer write. An attacker could exploit this vulnerability by submitting a crafted file that contains 7z content to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-120

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • clamav
  • secure_endpoint

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 1 mentions (2026-07-02); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Products
clamavsecure_endpoint

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-07-02: 1Mentions · 2026-07-09: 1Mentions · 2026-08-14: 1Patch / Workaround · 2026-07-02: 1Patch / Workaround · 2026-07-09: 1Technical Details · 2026-07-02: 1Technical Details · 2026-07-09: 1Technical Details · 2026-08-14: 107-0207-0908-14
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-07-021
Disclosure1
2026-07-091
Patch1
2026-08-141
Disclosure1
Full discourse3 posts
  • Security Arsenal, LLC@SecurityAr58409
    Disclosure

    🔒 #CyberSecurity CVE-2026-20215: ClamAV 7z Parsing Integer Overflow — Detection, Hardening, and … "The Zero Day Initiative has published ZDI-26-583, disclosing a remotely exploitable integer…" 🔗 https://securityarsenal.com/blog/cve-2026-20215-clamav-7z-parsing-integer-overflow-detection-hardening-and-remediation-guide #CyberSecurity #ThreatIntel #critical #zeroday #cve

    Post summary

    A zero‑day integer‑overflow flaw in ClamAV’s 7z parser (CVE‑2026‑20215) has been disclosed by the Zero Day Initiative, with a remediation guide linked in a blog post.

    0000097
    23 followersView on X
  • iototsecnews@iototsecnews
    Patch

    ClamAV の脆弱性 CVE-2026-20213/20214/20215 が FIX:サービス拒否 (DoS) の可能性 https://iototsecnews.jp/2026/07/02/multiple-clamav-vulnerabilities-allow-remote-attacker-to-cause-a-dos-condition/ セキュリティの要となる ClamAV において、 検査対象のデータを解析する内部処理の不備を原因とした深刻な問題が明らかになりました。この脆弱性 CVE-2026-20213/CVE-2026-20214/CVE-2026-20215 が悪用されると、 悪意のファイルを読み込む際に保護システムが突然停止してしまう恐れがあります。特定の環境では端末自体が応答しなくなるなど、防衛体制に大きな穴が空くリスクを伴います。安全な運用を維持するための対応策として、開発元から配布されている最新のコネクタへの更新を早期に適用し、常に最新の防御状態を保つように心がけてください。 #Cisco #ClamAV #CVE202620213 #CVE202620214 #CVE202620215 #Vulnerability

    Post summary

    The article announces several ClamAV CVEs that could cause a denial‑of‑service when malicious files are scanned and urges users to promptly apply vendor updates to mitigate the risk.

    00000120
    500 followersView on X
  • TECHEPAGES@techepages
    Disclosure

    🚨 Cisco warns of multiple high-severity ClamAV flaws (advisory cisco-sa-clamav-88cFYyxR) letting remote attackers crash the AV engine via malformed files. Key CVEs: - CVE-2026-20216 - CVE-2026-20213 - CVE-2026-20214 - CVE-2026-20215 - CVE-2026-20217 - CVE-2026-20243 - CVE-2026-20244 These vulnerabilities are fixed in ClamAV 1.5.3 / 1.4.5. Cisco Security 📁 Windows hit hardest (CVSS 7.5), endpoints may need a reboot. No workarounds; patch Secure Endpoint Connector now.

    Post summary

    Cisco has publicly disclosed multiple high‑severity ClamAV CVEs that allow remote attackers to crash the engine via malformed files, but no workarounds are available; patches are already provided in newer ClamAV releases.

    0000063
    22 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Appciscosecure_endpoint-linux-
Appciscosecure_endpoint-macos-
Appciscosecure_endpoint-windows-
Appclamavclamav---

Explore more