Cisco Secure Endpoint Connector Exposes Seven ClamAV Flaws, Two with Public PoCs Enabling Remote DoS
What Happened — Cisco disclosed seven vulnerabilities (CVE‑2026‑20337 to 20339, CVE‑2026‑20345 to 20348) in the open‑source ClamAV engine that powers its Secure Endpoint Connector on Windows, macOS and Linux. Two of the flaws (CVE‑2026‑20337 and CVE‑2026‑20338) have publicly released proof‑of‑concept code that allows an unauthenticated attacker to trigger a denial‑of‑service condition by submitting a crafted ZIP file.
Why It Matters for Compliance & Audit Readiness
- SOC 2 security controls require continuous monitoring of third‑party components; unpatched library flaws break the “Vulnerability Management” and “System Operations” criteria.
- Evidence of timely patching and control mapping is essential audit evidence; the existence of public PoCs turns a theoretical risk into a compliance‑critical event.
- Verisq’s Control Mapping capability lets you automatically align newly disclosed CVEs to your SOC 2 control set and generate continuous proof of remediation.
Who Is Affected — Enterprises that rely on Cisco Secure Endpoint Connector (or any product embedding ClamAV), spanning technology SaaS, financial services, healthcare, and other regulated sectors.
Recommended Actions
- Upgrade ClamAV to version 1.5.4 (or later) on all affected endpoints immediately.
- Re‑run your SOC 2 vulnerability‑management controls to verify remediation and capture evidence.
- Document the patch cycle in your continuous‑compliance platform to satisfy audit reviewers.
Technical Notes — The two exploitable flaws are out‑of‑bounds write and memory‑corruption bugs in the ZIP parser (CVSS 7.5). They are unauthenticated, remote DoS attacks triggered by crafted archive files. No wild‑use has been observed yet. Source: SecurityAffairs