### Summary
Multiple high-severity vulnerabilities have been identified in ClamAV file-format parsers used by affected Cisco Secure Endpoint products. The flaws involve out-of-bounds writes and reads, memory corruption, double-free conditions, and integer overflow during the scanning of crafted ZIP, PESpin, GPT, PDF, Mach-O, and XAR files. Successful exploitation could allow unauthenticated remote attackers to terminate the ClamAV scanning process and cause denial-of-service conditions.[/subscribe_to_unlock_form]
### Summary
Multiple high-severity vulnerabilities have been identified in ClamAV file-format parsers used by affected Cisco Secure Endpoint products. The flaws involve out-of-bounds writes and reads, memory corruption, double-free conditions, and integer overflow during the scanning of crafted ZIP, PESpin, GPT, PDF, Mach-O, and XAR files. Successful exploitation could allow unauthenticated remote attackers to terminate the ClamAV scanning process and cause denial-of-service conditions.[emaillocker id="1283"]
• CVE-2026-20337 with a CVSS score of 7.5 – An out-of-bounds write in the ClamAV ZIP parser can be triggered by a crafted ZIP file, causing the scanning process to terminate.
• CVE-2026-20338 with a CVSS score of 7.5 – Improper memory handling in the ZIP parser can result in a double-free condition and denial of service.
• CVE-2026-20339 with a CVSS score of 7.5 – An integer overflow in the PESpin parser can cause memory corruption and potentially terminate the ClamAV scanning process.
• CVE-2026-20345 with a CVSS score of 7.5 – Improper endian conversion handling in the GPT parser can result in an out-of-bounds buffer write and denial of service.
• CVE-2026-20346 with a CVSS score of 7.5 – Improper boundary checks in the PDF parser can cause an out-of-bounds buffer read and terminate the scanning process.
• CVE-2026-20347 with a CVSS score of 7.5 – Improper boundary checks in the Mach-O parser can result in an out-of-bounds buffer read and denial of service.
• CVE-2026-20348 with a CVSS score of 7.5 – Improper boundary checks in the XAR parser can cause memory corruption and terminate the ClamAV scanning process.
These vulnerabilities present a high risk to affected Cisco Secure Endpoint deployments, particularly Windows-based systems where ClamAV operates in a privileged security context. Proof-of-concept exploit code is available for CVE-2026-20337 and CVE-2026-20338, although no malicious exploitation is currently known. Organizations should apply the available Cisco security updates, as no workarounds are available.
We recommend you to upgrade affected Cisco Secure Endpoint products to Secure Endpoint Connector for Windows 8.6.2+, Linux 1.29.0+, Mac 1.27.2+, and Secure Endpoint Private Cloud 4.2.8+; ClamAV fixes are included in versions 1.5.3+ and 1.4.5+
The following reports contain further technical details:
[/emaillocker]