DoS Vulnerability in Zip Archive Parser of ClamAV
CVE-2026-20337
7.5HIGH
Key Information:
- Vendor
Cisco
- Status
- Vendor
- CVE Published:
- 7 August 2026
Badges
๐พ Exploit Exists๐ฐ News Worthy
What is CVE-2026-20337?
A vulnerability exists in the zip archive parser of ClamAV that may allow unauthenticated remote attackers to exploit improper boundary checks. This results in an out-of-bounds write condition during the scanning process, permitting the execution of crafted zip files to terminate the scanning process. Consequently, this leads to a Denial of Service (DoS) condition, affecting the availability of the software.
Affected Version(s)
Cisco Secure Endpoint 7.0.5
Cisco Secure Endpoint 6.2.19
Cisco Secure Endpoint 7.3.3
News Articles
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
- ๐ฐ
First article discovered by BleepingComputer
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved