Junglewise Threat Intelligence

CVE-2026-20214: Cisco ClamAV out-of-bounds write in FSG file parser

CVE-2026-20214 · Severity: high · CVSS 7.5 · Published 2026-07-01

Technologies: Cisco Secure Endpoint Connector for Windows, Cisco Secure Endpoint Connector for Mac, Cisco Systems, Inc. ClamAV, Cisco Secure Endpoint Connector for Linux. Vendors: Cisco.

Executive brief

A vulnerability in the ClamAV antivirus engine could allow an attacker to crash the scanning service by providing a specially crafted file. ClamAV is widely used to scan emails and files for malware; if the scanner crashes, it can stop protecting the system or cause the entire computer to become unresponsive. On Windows systems, this is particularly serious as it may require a manual reboot to restore security protections.

Technical details

A memory corruption vulnerability exists in the FSG (Fast Small Good) file format parser of ClamAV due to improper boundary checks during the scanning of compressed portable executable (PE) content. An unauthenticated remote attacker can exploit this by submitting a crafted FSG-compressed file, triggering an out-of-bounds buffer write. This results in the termination of the ClamAV scanning process, leading to a denial of service. On Windows platforms, where the process runs with higher privileges, this may lead to system instability or require a reboot. Cisco has released updates for affected products including Secure Endpoint Connectors.

Affected products

  • Cisco Systems, Inc. ClamAV
  • Cisco Secure Endpoint Connector for Windows Prior to 8.6.2
  • Cisco Secure Endpoint Connector for Linux Prior to 1.29.0
  • Cisco Secure Endpoint Connector for Mac Prior to 1.27.2

Timeline

  • 2026-07-01: advisory: Cisco published the security advisory.
  • 2026-07-01: disclosed: CVE-2026-20214 published to NVD.

References

Related threats