
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20031 is a denial-of-service (DoS) vulnerability in the HTML Cascading Style Sheets (CSS) module of ClamAV, affecting Cisco Secure Endpoint Connector for Linux, Mac, and Windows, as well as Cisco Secure Endpoint Private Cloud. The flaw stems from improper error handling when splitting UTF-8 strings, allowing an unauthenticated remote attacker to terminate the ClamAV scanning process by submitting a crafted HTML file. It was discovered during internal Cisco security testing and publicly disclosed on March 4, 2026. The vulnerability carries a CVSS v3.1 base score of 5.3 (Medium) (Cisco Advisory, Red Hat Bugzilla).
The root cause is classified as CWE-248 (Uncaught Exception), arising from improper error handling in ClamAV's HTML CSS parsing module when processing UTF-8 string splitting operations. An attacker exploits this by submitting a specially crafted HTML file to any service or endpoint that passes files to ClamAV for scanning — no authentication or user interaction is required. The malformed input triggers an unhandled exception that causes the ClamAV scanning process to crash. Cisco Bug IDs CSCwr70252, CSCwr70255, CSCwr70257, and CSCwr70268 track the issue across affected platforms (Cisco Advisory).
Successful exploitation causes the ClamAV scanning process to crash, disrupting or halting antivirus scanning operations on the affected device. The impact is limited to availability — there is no confidentiality or integrity impact, and overall system stability is not affected. However, a crashed scanning process could delay or prevent detection of malware, potentially creating a window for other threats to go undetected on endpoints running Cisco Secure Endpoint Connector (Cisco Advisory).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported. Cisco PSIRT confirmed it is not aware of any public announcements or malicious use of this vulnerability at the time of disclosure. The EPSS score is approximately 0.094%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Cisco Advisory, Feedly).
clamd, clamscan, or the Cisco Secure Endpoint connector scanning service) without a clear system-level cause.Cisco has released fixed software versions addressing this vulnerability: Secure Endpoint Connector for Linux 1.28.1, Secure Endpoint Connector for Mac 1.27.2, Secure Endpoint Connector for Windows 8.6.0, and Secure Endpoint Private Cloud 4.2.7 or earlier with updated connectors. Updated connector releases are available through the Cisco Secure Endpoint portal and may be applied automatically depending on configured policy. Cisco confirms there are no workarounds available; upgrading to a fixed release is the only remediation (Cisco Advisory). Standalone ClamAV users should update to version 1.5.2 or later, as patched releases are available via the ClamAV GitHub releases. Linux distribution users (openSUSE, Ubuntu, Amazon Linux) should apply vendor-provided security updates.
The vulnerability received routine coverage from Linux distribution security channels, with openSUSE, Ubuntu, and Amazon Linux all issuing security advisories and package updates. Security aggregators including Tenable (Nessus plugins 302191, 311213, 311324), Qualys (761700), and VulDB tracked the issue. Coverage was largely technical and low-profile, consistent with a medium-severity DoS vulnerability with no known exploitation (Cisco Advisory).
Fix availability across major Linux distributions and their releases.
bionic (esm-infra)
clamav
devel
clamav
focal (esm-infra)
clamav
jammy
clamav: 1.4.4+dfsg-0ubuntu0.22.04.1
noble
clamav: 1.4.4+dfsg-0ubuntu0.24.04.1
questing
clamav: 1.4.4+dfsg-0ubuntu0.25.10.1
resolute
clamav: 1.4.4+dfsg-0ubuntu0.26.04.1
trusty (esm-infra-legacy)
clamav
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."