Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Cisco Discloses Critical ClamAV Vulnerabilities

Cisco Discloses Critical ClamAV Vulnerabilities

Posted on August 10, 2026 By CWS

Cisco has issued a warning regarding significant vulnerabilities in its Secure Endpoint Connector software, impacting Windows, macOS, and Linux systems. The alert, released on Friday, highlights seven flaws in ClamAV, a widely used open-source malware detection tool. Notably, two of these vulnerabilities have publicly available proof-of-concept (PoC) code, raising the urgency for users to take action.

Details of the ClamAV Vulnerabilities

ClamAV, known for its cross-platform malware detection capabilities, is susceptible to several security issues tracked from CVE-2026-20337 to CVE-2026-20339 and CVE-2026-20345 to CVE-2026-20348. These defects reside within the parsers for ZIP, GPT, PESpin, PDF, Mach-O, and XAR file formats. Cisco has addressed these vulnerabilities in ClamAV version 1.5.4, which also remedies a critical path traversal flaw in WinRAR for Windows that could allow arbitrary code execution.

The release of patches was swiftly followed by Cisco’s advisory, highlighting the existence of PoC code specifically for CVE-2026-20337 and CVE-2026-20338. Users are urged to apply the updates promptly, as no immediate workarounds are available for these issues.

Impact on Different Platforms

According to Cisco, the impact of these vulnerabilities varies by platform. On Windows, the risks are classified as high-severity due to the privileged security context in which ClamAV operates. Conversely, the risks are lower on macOS and Linux, where ClamAV runs with reduced privileges, posing a medium-severity threat.

While the Secure Endpoint Private Cloud is not affected, the Secure Endpoint Connector software is vulnerable. Cisco advises customers to deploy the available patches through Secure Endpoint Private Cloud releases 4.2.8 and later to secure their systems effectively.

Future Security Measures

As of now, Cisco reports no active exploitation of these vulnerabilities in the wild. However, the company plans to release comprehensive security updates for all affected products by August. Users are encouraged to remain vigilant and implement the patching recommendations to mitigate potential risks.

The advisory serves as a critical reminder of the importance of timely software updates in maintaining robust cybersecurity defenses. Cisco’s proactive disclosure underlines the ongoing need to address vulnerabilities swiftly to protect against emerging threats.

Security Week News Tags:Cisco, ClamAV, Cybersecurity, endpoint security, Linux, macOS, Patches, proof-of-concept, Security, software update, Vulnerabilities, Windows

Post navigation

Previous Post: TrueConf Server Vulnerabilities Exploited by Cybercriminals
Next Post: Critical Progress LoadMaster Vulnerability Alert: Exploitation Detected

Related Posts

Hundreds of Salesforce Customers Hit by Widespread Data Theft Campaign Hundreds of Salesforce Customers Hit by Widespread Data Theft Campaign Security Week News
Ukrainian Extradited to US Faces Charges in Jabber Zeus Cybercrime Case Ukrainian Extradited to US Faces Charges in Jabber Zeus Cybercrime Case Security Week News
Sublime Security Raises 0 Million for Email Security Platform Sublime Security Raises $150 Million for Email Security Platform Security Week News
Adobe Patches 29 Vulnerabilities – SecurityWeek Adobe Patches 29 Vulnerabilities – SecurityWeek Security Week News
Oracle Enhances Security with Monthly Patch Updates Oracle Enhances Security with Monthly Patch Updates Security Week News
SAP Addresses Critical Vulnerabilities in S/4HANA SAP Addresses Critical Vulnerabilities in S/4HANA Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • CISA Demands Urgent Fix for Progress LoadMaster Flaw
  • AI Threats, Metabase 0-Day, and Router Backdoors Highlight Cybersecurity Concerns
  • Critical Progress LoadMaster Vulnerability Alert: Exploitation Detected
  • Cisco Discloses Critical ClamAV Vulnerabilities
  • TrueConf Server Vulnerabilities Exploited by Cybercriminals

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • CISA Demands Urgent Fix for Progress LoadMaster Flaw
  • AI Threats, Metabase 0-Day, and Router Backdoors Highlight Cybersecurity Concerns
  • Critical Progress LoadMaster Vulnerability Alert: Exploitation Detected
  • Cisco Discloses Critical ClamAV Vulnerabilities
  • TrueConf Server Vulnerabilities Exploited by Cybercriminals

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark