Cisco ClamAV ZIP Parser Denial of Service Vulnerabilities with Public Exploits (CVE-2026-20337 / CVE-2026-20338)
Scope: Cisco Secure Endpoint Connector for Windows, Mac, and Linux (ClamAV Versions Prior to 1.4.4 and 1.0.9)
Severity: High
Cisco disclosed two high-severity vulnerabilities today, August 11, 2026, in the ClamAV antivirus engine embedded in Cisco Secure Endpoint Connector, both with public exploit code already available: CVE-2026-20337, an improper boundary check in the ZIP archive parser, and CVE-2026-20338, a memory handling flaw in the same component, both exploitable by unauthenticated remote attackers who can send a malicious ZIP archive to a protected endpoint, crashing the ClamAV scanning process entirely and disabling malware detection across all endpoints protected by the affected connector. Because ClamAV is a widely deployed open-source antivirus engine used across Linux servers, developer workstations, and mail gateways in addition to the Cisco Secure Endpoint product, the exposure surface extends beyond Cisco deployments. Organizations must update Cisco Secure Endpoint Connector and any standalone ClamAV installations to the patched versions referenced in Cisco's August 11 advisory, and where immediate patching is not possible, configure supplementary malware scanning via an alternative detection engine until the update is applied.
The Uganda National CERT and Coordination Center (CERT.UG/CC) encourages users and administrators to review the recommendations and apply the necessary updates.