CVE-2026-20337 and CVE-2026-20338 are two high-severity flaws in ClamAV's ZIP archive parser that, according to Cisco, can be weaponized by an unauthenticated remote actor to force the antivirus scanner to crash — and proof-of-concept exploit code is already public.
Cisco PSIRT: proof-of-concept available, no evidence of active exploitation
Cisco's Product Security Incident Response Team (PSIRT) published an advisory saying the two vulnerabilities allow remote, unauthenticated attackers to submit specially crafted ZIP files for scanning and cause the ClamAV scanning process to terminate, creating a denial-of-service (DoS) condition on affected software. Cisco warned: "An attacker could exploit this vulnerability by submitting a crafted zip file for scanning. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software."
The PSIRT also stated that it is aware proof-of-concept (PoC) exploit code is available for CVE-2026-20337 and CVE-2026-20338, but that it currently has no evidence the vulnerabilities have been exploited in the wild.
ClamAV ZIP archive parser: causes and affected releases
Cisco attributes the two flaws to implementation errors in ClamAV's ZIP archive parser: CVE-2026-20337 stems from improper boundary checks, while CVE-2026-20338 is due to improper memory handling. Both are present in ClamAV versions 1.5.0 through 1.5.3. The ClamAV project released a fix in version 1.5.4 on August 7.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scramblePlatform impact and Secure Endpoint Connector updates
Cisco's advisory narrows the highest security impact to Windows platforms, noting that Windows is the only platform among those Cisco tracks that "run the ClamAV scanning process in a privileged security context." Because of that privileged execution, Cisco characterizes the security impact as high for Windows.
For customers using Cisco Secure Endpoint Connector, Cisco said there are no workarounds for CVE-2026-20337 and CVE-2026-20338, and it plans to release product updates later this month to address the flaws in affected Secure Endpoint Connector versions for Windows, Linux, and Mac.
Cisco's broader recent ClamAV fixes and prior incidents
On the same Friday Cisco published the advisory for the two ZIP parser flaws, it also released patches for five other ClamAV vulnerabilities that could be abused to trigger DoS conditions by submitting specially crafted XAR, Mach‑O, PDF, GPT, and PESpin files for scanning. Cisco further noted it patched another ClamAV DoS vulnerability in January 2025 that also had PoC exploit code available and could be abused to terminate the ClamAV antivirus scanner, preventing or delaying further scanning operations.
What this means for security teams, affected enterprises, and adversaries
- Security teams: ClamAV 1.5.4, released August 7, contains the fixes for CVE-2026-20337 and CVE-2026-20338. Teams that rely on ClamAV for file scanning should track deployment of that fixed build and monitor Cisco's promised Secure Endpoint Connector updates later this month. Cisco's statement that no workarounds exist for these specific flaws means organizations must rely on version updates rather than configuration changes to mitigate the issues.
- Affected enterprises and procurement leads: Windows endpoints where ClamAV runs in a privileged security context face the highest immediate impact, per Cisco. Enterprises should plan to prioritize patches on Windows hosts and to schedule Cisco Secure Endpoint Connector updates when they become available.
- Adversaries and threat actors: Public PoC exploit code exists, which lowers the technical barrier for attackers to attempt denial-of-service attacks against systems that automatically scan untrusted ZIP files. Cisco reports no evidence of exploitation so far, but the presence of PoC makes rapid patching more urgent.
Two closing facts sharpen the choice facing defenders: Cisco has recently moved to patch multiple ClamAV flaws, and its track record of tracking exploitation is highlighted by the U.S. Cybersecurity and Infrastructure Security Agency's tally that, since November 2021, it has tagged 95 Cisco vulnerabilities as actively exploited in attacks, six of those used in ransomware operations. With PoC code public and no available workarounds for these ZIP parser flaws, the next few weeks will show whether rapid patching and forthcoming Secure Endpoint updates blunt exploitation attempts.




