High‑Severity DoS Vulnerabilities in Cisco’s ClamAV‑Based Secure Endpoint Connector (CVE‑2026‑20337/20338)
What Happened — Cisco disclosed two high‑severity vulnerabilities (CVE‑2026‑20337, CVE‑2026‑20338) in the ZIP‑archive parser of ClamAV 1.5.0‑1.5.3, the engine powering the Secure Endpoint Connector. The flaws allow an unauthenticated remote attacker to submit a crafted ZIP file that crashes the scanner, creating a denial‑of‑service condition. Proof‑of‑concept exploit code is publicly available, and Cisco released a patch in ClamAV 1.5.4 on August 7 2026.
Why It Matters for Compliance & Audit Readiness
- SOC 2 CC6.2 (Vulnerability Management) requires documented, timely remediation of known flaws; the public exploits underscore the need for continuous patch tracking.
- Evidence of patch deployment and verification must be retained to satisfy auditors’ demand for a defensible remediation workflow.
- Mapping this vulnerability to your control inventory enables automated evidence collection for the “Control Mapping” capability in Verisq’s Trust Center.
Who Is Affected — Organizations that deploy Cisco Secure Endpoint Connector across Windows, Linux, or macOS environments – spanning technology, financial services, healthcare, and other sectors that rely on endpoint protection.
Recommended Actions
- Upgrade ClamAV to version 1.5.4 (or later) on all affected endpoints immediately.
- Verify patch status through automated inventory tools and record the change in your change‑management system.
- Map the remediation activity to SOC 2 CC6.2 and capture screenshots, patch logs, and validation test results as audit evidence.
- Enable continuous vulnerability scanning to detect any future unpatched libraries.
Source: BleepingComputer
Technical Notes — The vulnerabilities stem from improper boundary checks and memory handling in ClamAV’s ZIP parser. They affect ClamAV 1.5.0‑1.5.3; exploitation is possible via a crafted ZIP file, causing a DoS on Windows where the scanner runs with privileged rights. No data breach has been reported. Source: Cisco PSIRT advisory