AL
Analyst accessPublic view · sign in

Vulnerability threat dossier

CVE-2026-20337

Vendor unknownProduct mapping pending

A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper boundary checks for content in zip files during scanning, which may result in an out-of-bounds write condition. An attacker could exploit this vulnerability by submitting a crafted zip file for scanning. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.

VTP deterministic threat19.6of 100 · CVSS excluded

VTP analyst assessment

No AI candidate assessment for this subject

AI-assisted analytical recommendationDoes not set factual exploitation state
AI classificationNO ALERT
AI priorityNONE
AI confidenceUnknown
Public exploitation · VTP factUNKNOWN

Assessment

The latest persisted AI review did not propose this CVE for analyst escalation. Deterministic monitoring remains authoritative for the factual states below.

Why it matters

Unknown from persisted AI analysis.

Evidence

No AI candidate evidence set is persisted for this CVE.

Uncertainties

No first-party sensor telemetry is configured. Local exploitation observation is unknown.

Next watchpoint · deterministic

Independent primary confirmation of active exploitation would materially change this assessment.

AI analysis history (0)
    Technical severityUNKNOWNCVSS 7.5 · technical context
    Public exploitationUNKNOWNGlobal public evidence
    Exploit maturityPOCReliability not implied
    EPSS0.0029th percentile · prediction
    Evidence confidence60%Strongest independent active claim
    VelocitySTABLEMaterial events only
    First-party telemetryNo first-party sensor telemetry configured.
    Availability: NO_SENSOR_CONFIGURED · Evidence: UNKNOWN
    01

    VTP deterministic assessment

    Why this matters

    1. 01

      A proof of concept is reported; functional reliability is not established.

    2. 02

      EPSS is 0.00; this is predictive context, not exploitation evidence.

    3. 03

      No first-party sensor telemetry is configured; first-party observation is unknown.

    02

    Material change ledger

    What changed

    VENDOR ADVISORYNew vendor advisory
    CERT ADVISORYNew CERT advisory
    03

    Claim provenance

    Evidence and source independence

    4publications detected
    4underlying evidence chains

    2 primary sources · 0 dependent secondary reports · 2 reports with unresolved independence. Repetition remains visible without multiplying confirmation.

    Source claimPOC AVAILABLEPUBLICATION REPORTS POC
    60%claim confidence
    UNKNOWNreport:ba39c18b07faa9a6debb0a9ce4659cae5b577d3e5c3f6869a13cf19260c53c3cACTIVE
    Evidence
    04

    Event history

    Threat timeline

    1. 11:0311 Aug
      POC AVAILABLE

      Poc Available

      BleepingComputer supplied a deterministically extracted signal; review the linked evidence before escalation.

    2. 16:0310 Aug
      VENDOR ADVISORY

      New vendor advisory

      Cisco Product Security Incident Response Team published evidence linked to CVE-2026-20337.

    3. 00:0010 Aug
      CERT ADVISORY

      New CERT advisory

      CERT-FR published evidence linked to CVE-2026-20337.

    05

    Original publications

    Source record

    Cisco warns of high-severity ClamAV flaws with public exploits

    Cisco warned of two high-severity vulnerabilities affecting the Secure Endpoint Connector that allow threat actors to crash the ClamAV scanning process in denial-of-service (DoS) attacks. [...]

    CVE-2026-20337CVE-2026-20338
    Separate evidence group
    Original

    ClamAV Vulnerabilities Affecting Cisco Products: August 2026

    Multiple vulnerabilities in ClamAV could allow a remote attacker to cause a denial of service (DoS) condition, interrupting scanning operations.  For more information about these vulnerabilities, see the Details section of this advisory. For additional information on these vulnerabilities in ClamAV, see the ClamAV blog . Cisco plans to release software updates that address these vulnerabilities in affected Cisco platforms. There are no workarounds that address these vulnerabilities. Notes: The Security Impact Rating (SIR) for these vulnerabilities is High for Windows-based platforms only because those platforms run the ClamAV scanning process in a privileged security context. The platforms that are highly impacted include Cisco Secure Endpoint Connector for Windows. The SIR for these vulnerabilities is Medium on other platforms, including Linux and Mac platforms, because those platforms run the ClamAV scanning process in a lower-privileged security context. The affected platforms include Secure Endpoint Connector for Linux and Mac. Cisco Secure Endpoint Private Cloud itself is not impacted by these vulnerabilities. However, the Cisco Secure Endpoint Connector software that is distributed from the device is impacted. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-WuuvVd26 <br/>Security Impact Rating: High <br/>CVE: CVE-2026-20337,CVE-2026-20338,CVE-2026-20339,CVE-2026-20345,CVE-2026-20346,CVE-2026-20347,CVE-2026-20348

    CVE-2026-20337CVE-2026-20338CVE-2026-20339CVE-2026-20345CVE-2026-20346CVE-2026-20347CVE-2026-20348
    Separate evidence group
    Original

    Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC

    Remote, unauthenticated attackers could exploit the bugs to cause a denial-of-service (DoS) condition. The post Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC appeared first on SecurityWeek .

    CVE-2026-20337CVE-2026-20338CVE-2026-20339CVE-2026-20345CVE-2026-20348
    Separate evidence group
    Original

    Multiples vulnérabilités dans ClamAV (10 août 2026)

    De multiples vulnérabilités ont été découvertes dans ClamAV. Certaines d'entre elles permettent à un attaquant de provoquer une atteinte à la confidentialité des données, un déni de service et un problème de sécurité non spécifié par l'éditeur.

    CVE-2025-8088CVE-2026-20337CVE-2026-20338CVE-2026-20339CVE-2026-20345CVE-2026-20346CVE-2026-20347CVE-2026-20348
    Separate evidence group
    Original
    06

    Technical vulnerability data

    Context, not threat proof

    VTP threat score19.6vtp-threat-v1-public
    Public exploitation0 / 30
    EPSS prediction0.07 / 20
    Exploit availability7.5 / 15
    Source independence0 / 15
    Intelligence recency10 / 10
    Threat acceleration2 / 10
    CVSS technical severityExcluded
    CVSS
    7.5 · UNKNOWN
    Vector
    CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
    CWE
    CWE-120
    CPE records
    0
    Deterministic history records
    5
    Primary technical reference
    07

    Raw observations

    First-party sensor records

    No first-party sensor telemetry configured.