# Your Antivirus Has Seven Holes in It — Two Already Have Working Exploits
The software scanning your files for malware just became a target. Cisco disclosed seven vulnerabilities in ClamAV on Friday, all capable of crashing the scanning engine via crafted files — and for two of them, working proof-of-concept code is already circulating publicly before most Secure Endpoint deployments have been patched.
That timeline is the uncomfortable part.
## Seven Parsers, Seven Failures
ClamAV's attack surface, like all antivirus engines, is enormous by design. To detect malicious content in files, the scanner has to parse those files — deeply, recursively, in ways that closely mirror what the actual application would do. That means implementing readers for dozens of container formats. And where there are parsers, there are parser bugs.
This round covers six format-specific parsers: ZIP, GPT (the disk partitioning scheme), PESpin (a Windows executable packer), PDF, Mach-O (macOS binaries), and XAR (Apple's extensible archive format). The CVEs run from CVE-2026-20337 through CVE-2026-20339 and CVE-2026-20345 through CVE-2026-20348. All seven enable remote, unauthenticated denial-of-service — an attacker can send a crafted file through any channel ClamAV scans (email, web downloads, shared drives) and crash the scanning process.
None of them have a workaround. Cisco is explicit about that. The only path forward is patching to ClamAV 1.5.4, which landed the fixes. Cisco's own Secure Endpoint Connector products for Windows, macOS, and Linux are all in scope; Secure Endpoint Private Cloud itself is unaffected, but the connector software it pushes to endpoints is.
## Why Windows Gets the Asterisk
Cisco rates the risk as high on Windows and medium everywhere else, and the reason is architectural. On macOS and Linux, ClamAV's scanning process runs with reduced privileges — if it crashes, the blast radius is limited. On Windows, Cisco's Secure Endpoint Connector runs the scanning process in a privileged security context.
That matters for two reasons. First, a crash in a privileged process is noisier and harder to recover from cleanly. Second — and this is the piece most advisories gloss over — privilege elevation bugs often follow availability bugs. Today's DoS in a high-privilege process is tomorrow's stepping stone if someone finds a memory corruption angle that the original parser flaw enabled. It's not a given, but it's exactly the kind of vulnerability chain that makes "just a DoS" a phrase security teams have learned to mistrust.
To be clear: Cisco says it has no indication these bugs are being exploited right now. But "no evidence of exploitation" is a statement about yesterday, and the PoC clock is already running.
## The PoC Gap
Here's the operational problem: two of these seven bugs — CVE-2026-20337 and CVE-2026-20338, both in the ZIP parser — have publicly available proof-of-concept code. Cisco published its advisory shortly after ClamAV 1.5.4 dropped, which means the disclosure and the fix arrived together. But enterprise patching doesn't work that way.
Secure Endpoint deployments receive updates pushed from the cloud. Cisco says patches will be rolled out in August for all affected products — meaning the window between "PoC is public" and "patch is on your endpoint" could be days or weeks depending on how aggressively an organization has configured update delivery. For environments with manual approval gates on endpoint updates, or where IT is stretched thin in August, that gap widens further.
A crafted ZIP file delivered via phishing email, shared document link, or malicious download — the bread-and-butter of attacker playbooks — is all it takes to trigger CVE-2026-20337 or CVE-2026-20338. ClamAV will scan the attachment. That's the attack.
## The Recurring Irony of Security Tool Parser Bugs
This isn't a ClamAV-specific problem. It's a structural one baked into how antivirus and endpoint detection software works.
A partial list of the pattern: Sophos, Symantec, Kaspersky, ESET, Trend Micro, and Avast have all shipped remotely exploitable parser vulnerabilities in the past decade — often in the exact same file format categories that showed up this week. Tavis Ormandy's Project Zero work on AV engines from 2016 onward documented the phenomenon with clinical precision: security software runs with high privilege, parses untrusted content, and does so at a scale that makes comprehensive fuzzing extremely difficult. The attack surface is, structurally, ideal for finding bugs.
ClamAV's open-source nature is actually an advantage in this regard — the code is auditable and community-reviewed in ways that closed engines can't match. But it also means vulnerabilities surface faster and researchers can build PoCs quickly once a patch diff is public. The transparency cuts both ways.
## What Defenders Should Do Right Now
The action items here are narrow but urgent:
---
## HackWire Analysis
What makes this advisory worth sitting with is the combination that Cisco is, to their credit, being transparent about: seven vulnerabilities, public PoC code for two of them, no workarounds, and a patch delivery model that depends on enterprise update pipelines doing their job efficiently.
The ZIP parser bugs are the ones to watch. ZIP is ubiquitous — it's an email attachment format, a software distribution format, a container for malicious payloads masquerading as legitimate archives. Every major threat actor toolkit touches ZIP at some point. Choosing ZIP as your exploitation vector when targeting an antivirus scanner isn't accidental; it's the format most likely to be fed to the scanner under normal operational conditions.
The broader pattern this fits is the persistent failure of security vendors — across the industry, not just Cisco — to treat their own software's attack surface with the same rigor they'd apply to a customer-facing web application. AV engines are effectively privilege-holding, always-on, input-parsing services. They should be fuzz-tested continuously against every format they support, and parser subsystems should run with the minimum privilege required. Progress is being made on this industry-wide, but slowly.
For the security operations community, the takeaway isn't panic — it's that endpoint protection software needs to be part of your vulnerability management program, not exempt from it. When your AV is the thing with the unpatched CVE and public PoC, the usual advice ("let your AV handle it") doesn't apply. You need visibility into the security software itself, not just what it's scanning for.
The August patch window Cisco cited is vague enough to be uncomfortable. Demand specificity from your account team about when your deployment class receives the automated update. Don't assume it's happening.
— HackWire Editorial
---
## Related Coverage