
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20215 is a memory corruption vulnerability in the 7z file format parser of ClamAV, classified as "ClamAV 7z File Format Processing Memory Corruption Vulnerability." It allows an unauthenticated, remote attacker to cause a denial of service (DoS) condition — and potentially other expanded impacts — by submitting a crafted 7z file for scanning. Affected ClamAV versions include 1.5.x before 1.5.3 and all versions before 1.4.5; Cisco Secure Endpoint Connector for Windows (before 8.6.2), Linux (before 1.29.0), and macOS (before 1.27.2) are also affected. The vulnerability was publicly disclosed on July 1, 2026, with patches released the same day. It carries a CVSS v3.1 base score of 7.5 (High) (Cisco Advisory, GitHub Advisory).
The root cause is improper boundary checking when parsing 7z archive content during scanning, classified as CWE-120 (Buffer Copy without Checking Size of Input — Classic Buffer Overflow). The flaw results in an out-of-bounds buffer write, which can corrupt memory and cause the ClamAV scanning process to terminate. The attack vector is network-based, requires no authentication, no user interaction, and low attack complexity — making it fully automatable. On Windows platforms, Cisco notes that similar memory corruption vulnerabilities have historically been leveraged for remote code execution, though no evidence of RCE has been demonstrated for this specific CVE; 32-bit Windows systems are at higher risk than modern 64-bit systems (Cisco Advisory, GitHub Advisory).
Successful exploitation causes the ClamAV scanning process to terminate, resulting in a DoS condition that disables malware detection capabilities on the affected system. On Cisco Secure Endpoint Connector for Windows, the scanning engine runs in a privileged context, meaning a crash may render the endpoint unresponsive and require manual intervention such as a system reboot to recover. On Linux and macOS platforms, the scanning process runs in a lower-privileged context, so exploitation causes scanning disruption without broader system instability. There is no direct confidentiality or integrity impact, but disabling endpoint scanning creates a window for undetected malware activity (Cisco Advisory).
As of the time of disclosure, Cisco PSIRT is not aware of any public announcements or malicious use of this vulnerability in the wild (Cisco Advisory). No public proof-of-concept exploit code is known to exist. The EPSS score is approximately 0.389%, indicating a low near-term probability of exploitation (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The attack is classified as automatable (no user interaction required), which lowers the barrier for opportunistic exploitation if a PoC were to emerge.
clamd, clamscan) without a corresponding scheduled stop or update event; repeated process crashes in a short timeframe./var/log/clamav/clamav.log or equivalent) showing segmentation faults, memory corruption errors, or abrupt process exits when scanning 7z files; system logs (e.g., Windows Event Log, syslog) recording abnormal ClamAV process termination.Cisco has released fixed versions addressing this vulnerability: ClamAV 1.5.3 and 1.4.5; Cisco Secure Endpoint Connector for Windows 8.6.2, for Linux 1.29.0, and for macOS 1.27.2. Cisco Secure Endpoint Private Cloud itself is not impacted, but connector software distributed from it should be updated to version 4.2.8 or later. There are no workarounds available — upgrading to a patched release is the only remediation. Depending on configured policy, Cisco Secure Endpoint Connector may update automatically; administrators should verify deployment status through the Cisco Secure Endpoint portal. As a secondary measure, implementing network-level controls to restrict which sources can submit files for scanning can reduce exposure (Cisco Advisory, ClamAV Blog).
Cisco credited multiple researchers for discovering this and related vulnerabilities: David Pokora of Trail of Bits (working with Anthropic), Niv Moshe working with TrendAI Zero Day Initiative, and Calif.io in collaboration with Claude and Anthropic Research, among others — highlighting the growing role of AI-assisted vulnerability research (Cisco Advisory). Security news outlets including Help Net Security, VPN Central, and Linuxiac covered the broader ClamAV patch release (versions 1.5.3 and 1.4.5), noting that seven legacy vulnerabilities were addressed simultaneously. The Hacker News included the ClamAV patches in its weekly security recap, reflecting moderate community interest. Red Hat and SUSE both issued advisories and package updates for their distributions, and Ubuntu published security notice USN-8517-1 addressing the affected ClamAV packages.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."