Close Menu

    Subscribe to Updates

    Get the latest Tech news from SynapseFlow

    What's Hot

    Extension Banned for Stealing AI Chats Returns to Chrome Store, Resumes Malicious Activities

    August 11, 2026

    Semianalysis Agrees With NextBigfuture $300B Per Year for SpaceX by End of 2027 – NextBigFuture.com

    August 11, 2026

    YouTube just doubled the grind before creators can start making ad money

    August 11, 2026
    Facebook X (Twitter) Instagram
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    Facebook X (Twitter) Instagram YouTube
    synapseflow.co.uksynapseflow.co.uk
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    synapseflow.co.uksynapseflow.co.uk
    Home»Cybersecurity»Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC
    Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC
    Cybersecurity

    Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC

    The Tech GuyBy The Tech GuyAugust 11, 2026No Comments2 Mins Read0 Views
    Share
    Facebook Twitter LinkedIn Pinterest Email
    Advertisement


    Cisco on Friday warned that its Secure Endpoint Connector products on Windows, macOS, and Linux are affected by seven ClamAV vulnerabilities that could lead to denial-of-service (DoS) conditions, including two with public proof-of-concept (PoC) code.

    Advertisement

    ClamAV (Clam AntiVirus) is an open source, cross-platform malware detection engine that provides a multi-threaded virtual scanner, email filtering, and automatic database updates.

    The security defects, tracked as CVE-2026-20337 to CVE-2026-20339 and CVE-2026-20345 to CVE-2026-20348, were discovered in ClamAV’s parsers for ZIP, GPT, PESpin, PDF, Mach-O, and XAR file formats.

    Patches for the bugs were included in ClamAV version 1.5.4, which also includes the patch for a path traversal weakness in WinRAR for Windows that could lead to arbitrary code execution.

    Shortly after ClamAV rolled out the fixes, Cisco published an advisory warning that PoC code targeting CVE-2026-20337 and CVE-2026-20338 exists.

    According to the company, no workaround exists for any of the vulnerabilities and security updates addressing them will be rolled out in August for all Secure Endpoint Connector products.

    Advertisement. Scroll to continue reading.

    The security defects, Cisco says, pose a high risk to Windows users, “because those platforms run the ClamAV scanning process in a privileged security context.”

    On macOS and Linux, the flaws pose a medium-severity risk, as the ClamAV scanning process runs on them with lower privileges.

    Secure Endpoint Private Cloud is not affected, but the Secure Endpoint Connector software is impacted, and customers are advised to push the available patches (included in Secure Endpoint Private Cloud releases 4.2.8 and later) from the cloud to their endpoints.

    The company says it is not aware of any of these vulnerabilities being exploited in the wild.

    Related: Metabase Patches Vulnerability Exploited as Zero-Day

    Related: CISA Urges Immediate Patching of Exploited Progress LoadMaster Vulnerability

    Related: Critical Paperclip Flaw Allowed Admin Access, Code Execution

    Related: Cisco Patches Critical SD-WAN, IOS XE, FMC Vulnerabilities

    Advertisement
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    The Tech Guy
    • Website

    Related Posts

    Extension Banned for Stealing AI Chats Returns to Chrome Store, Resumes Malicious Activities

    August 11, 2026

    Stealthium Targets Security Blind Spots in AI Accelerators and Neo-Clouds

    August 10, 2026

    OpenAI’s Upcoming Astra Model Raises Autonomous Cyberattack Concerns

    August 10, 2026

    Metabase Patches Vulnerability Exploited as Zero-Day

    August 10, 2026

    Critical Flaws Discovered in Belgian eID Software Used by 2 Million People

    August 10, 2026

    Critical Vulnerabilities Patched With Chrome 151 Update

    August 9, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    You don’t need a NAS to self-host — I proved it with hardware from my closet

    June 7, 2026391 Views

    Spotify is giving one of its best playlists a big visual upgrade to give subscribers ‘a closer connection’ to its New Music Friday curators — and I think it could be the update it’s always needed

    June 12, 2026210 Views

    The iPad Air brand makes no sense – it needs a rethink

    October 12, 202516 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Advertisement
    About Us
    About Us

    SynapseFlow brings you the latest updates in Technology, AI, and Gadgets from innovations and reviews to future trends. Stay smart, stay updated with the tech world every day!

    Our Picks

    Extension Banned for Stealing AI Chats Returns to Chrome Store, Resumes Malicious Activities

    August 11, 2026

    Semianalysis Agrees With NextBigfuture $300B Per Year for SpaceX by End of 2027 – NextBigFuture.com

    August 11, 2026

    YouTube just doubled the grind before creators can start making ad money

    August 11, 2026
    categories
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    Facebook X (Twitter) Instagram Pinterest YouTube Dribbble
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    © 2026 SynapseFlow All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.