CVE-2026-20216Disclosure(cisco / clamav)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch cisco clamav systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability in the InstallShield file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper handling of temporary resources during file scanning. An attacker could exploit this vulnerability by submitting a crafted InstallShield file to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to terminate the ClamAV scanning process and temporarily consume available system resources, resulting in a DoS condition on the affected software.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-770

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • clamav
  • secure_endpoint

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Products
clamavsecure_endpoint

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-07-02: 1Patch / Workaround · 2026-07-02: 1Technical Details · 2026-07-02: 107-02
Signal classification1 categories
Disclosure
1100.0%
Full discourse1 post
  • TECHEPAGES@techepages
    Disclosure

    🚨 Cisco warns of multiple high-severity ClamAV flaws (advisory cisco-sa-clamav-88cFYyxR) letting remote attackers crash the AV engine via malformed files. Key CVEs: - CVE-2026-20216 - CVE-2026-20213 - CVE-2026-20214 - CVE-2026-20215 - CVE-2026-20217 - CVE-2026-20243 - CVE-2026-20244 These vulnerabilities are fixed in ClamAV 1.5.3 / 1.4.5. Cisco Security 📁 Windows hit hardest (CVSS 7.5), endpoints may need a reboot. No workarounds; patch Secure Endpoint Connector now.

    Post summary

    Cisco announced several high‑severity ClamAV CVEs that allow remote attackers to crash the engine via malformed files, with fixes available in ClamAV 1.5.3 / 1.4.5 and a patch now applied to Secure Endpoint Connector.

    0000063
    22 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Appciscosecure_endpoint-linux-
Appciscosecure_endpoint-macos-
Appciscosecure_endpoint-windows-
Appclamavclamav---

Explore more