
[CIVN-2026-0406] Multiple vulnerabilities in ClamAV
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Multiple vulnerabilities in ClamAV
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: HIGH
Software Affected
Secure Endpoint Connector for Linux.
Secure Endpoint Connector for Mac.
Secure Endpoint Connector for Windows.
Overview
Multiple vulnerabilities have been reported in ClamAV, which could allow a remote attacker to cause a denial of service (DoS) condition, interrupting scanning operations on the affected system.
Target Audience:
All end-user organizations and individuals using the affected Secure Endpoint Connector products.
Risk Assessment:
High risk of denial-of-service, interruption of malware-scanning operations, and memory corruption.
Impact Assessment:
Potential impact on confidentiality, integrity, and availability of the system.
Description
ClamAV is an open-source cross-platform antivirus software toolkit owned and maintained by Cisco.
Multiple vulnerabilities exist in ClamAV, due to improper boundary checking, memory handling, integer overflow, and improper processing of specially crafted file formats.
Successful exploitation of these vulnerabilities could allow a remote attacker to cause a denial of service (DoS) condition, interrupting scanning operations on an affected system.
Solution
Apply appropriate updates as mentioned by the vendor as and when available:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-WuuvVd26
Vendor Information
CISCO
https://www.cisco.com/
References
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-WuuvVd26
CVE Name
CVE-2026-20337
CVE-2026-20338
CVE-2026-20339
CVE-2026-20345
CVE-2026-20346
CVE-2026-20347
CVE-2026-20348
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmp8f44ACgkQ3jCgcSdc
ys+f1A//Syy1gpzuRsatPSrJj/nzGCmooQQTywZA0L5ty6157B0VxurX6inRNbKo
Yh78XmChlmxjXXJuOMyA5hl6e7vHyqRyjFE3QKdWDOHe//qxzy+9vvQFyN7jRrLp
IiIMD8U6Q/He8D/z/cK8pj+HGQ2XbL8wqzMBOEvExVf4yhL4gu7d3Ok0DogVkbXa
KCj2flzzpV2cozSzk61M4gH42IFYA6L25vJsRuYQNOkeih93ppiOi+Hns+bbBMFm
PtA1GcILTyLkMMT5/3jpl3yF+S7Kx6gVQ5FdsukHmDwK/5iyyYJmu8RG1oNcIQSA
jJe2E9E+aA7FFdGpv0ECQSOJAi8dKtUPvdqYgbxCpQXKNCfHg72vQoIZpFmnJEKK
2fB8VcXOHiNZVTuB+FZvXdaoYltG9TjDhh223DxO5SQO+EGD63qfKhQGCGTT4sEP
gYPMtPHL8vZu1WHc2pPViLjkbivqB3fWKk/pcZ1AGZby2njjPRxxDC/iVy2ycmma
t83HIAfOSiSPgiDJL6/Vqz2LXGBWZ4r473EUOpj/bM13G/rmDBIVMsRfGT8PLSBj
n11ZcCqqcqJqz/sfpu7eXdwc5/pAGcdDtRTwLXQXRvTYTEW3SQB8Mh+8FZENFKCy
Co35UyXK1wqlSxoliyj/VzPT26hNpVh3BCeoD+Y26bU1YouWsSA=
=QGAX
—–END PGP SIGNATURE—–


