
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20216 is a Denial of Service (DoS) vulnerability in the InstallShield file format parser of ClamAV, allowing an unauthenticated remote attacker to terminate the ClamAV scanning process and temporarily exhaust system resources. It was disclosed on July 1, 2026, as part of a broader Cisco security advisory covering seven ClamAV vulnerabilities. Affected software includes ClamAV versions prior to 1.4.5 and 1.5.0–1.5.2 (fixed in 1.5.3), as well as Cisco Secure Endpoint Connector for Linux (before 1.29.0), Mac (before 1.27.2), and Windows (before 8.6.2). The vulnerability carries a CVSS v3.1 base score of 7.5 (High) (Cisco Advisory, GitHub Advisory).
The root cause is classified as CWE-770 (Allocation of Resources Without Limits or Throttling), specifically improper handling of temporary resources during InstallShield file scanning. An unauthenticated attacker can exploit this by submitting a specially crafted InstallShield file to any ClamAV-enabled scanning endpoint — no authentication, user interaction, or special privileges are required. The malformed file triggers uncontrolled resource consumption within the parser, causing the ClamAV scanning process to terminate. The vulnerability is network-accessible with low attack complexity, making it straightforward to exploit remotely. The researcher credited with discovering this specific vulnerability is "Mizu" (Cisco Advisory).
Successful exploitation results in termination of the ClamAV scanning process and temporary consumption of available system resources, causing a DoS condition on the affected software. On Windows-based platforms running Cisco Secure Endpoint Connector, the scanning engine runs in a privileged security context, meaning the endpoint may become unresponsive and require manual intervention (e.g., a system reboot) to recover — elevating the Security Impact Rating to High for those platforms. On Linux and Mac platforms, the scanning process runs in a lower-privileged context, so overall system stability is not affected, though scanning operations are delayed or prevented. There is no confidentiality or integrity impact; the vulnerability is purely an availability concern (Cisco Advisory).
No public proof-of-concept exploit code is known to exist, and Cisco PSIRT has confirmed no public announcements or malicious use of this vulnerability at the time of disclosure (Cisco Advisory). The EPSS score is approximately 0.389%, indicating a low near-term probability of exploitation in the wild (GitHub Advisory). The vulnerability is marked as automatable (no user interaction required) with network-level access, which lowers the barrier for exploitation if a PoC were to emerge. It is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
clamd crash or exit in /var/log/clamav/clamav.log); repeated scanning failures or timeouts logged around the same time.clamd or clamscan process when it should be running; unexpected respawn events for the ClamAV daemon..exe or .cab) files in directories monitored by ClamAV, particularly files with malformed headers.Cisco has released fixed versions to address this vulnerability: ClamAV 1.4.5 and 1.5.3, Cisco Secure Endpoint Connector for Linux 1.29.0, for Mac 1.27.2, and for Windows 8.6.2. Cisco Secure Endpoint Private Cloud is not directly impacted, but connector updates are distributed through the connector repository and applied via normal content update processes. There are no workarounds available — upgrading to a fixed release is the only remediation. As an interim measure, organizations should apply network segmentation to limit which systems can submit files for ClamAV scanning, and monitor ClamAV process stability for unexpected terminations (Cisco Advisory, GitHub Advisory).
The vulnerability was part of a broader July 2026 ClamAV security patch release (versions 1.5.3 and 1.4.5) that addressed seven legacy vulnerabilities, receiving coverage from security news outlets including Help Net Security, Linuxiac, and VPN Central (Help Net Security, Linuxiac). The ClamAV blog published an official announcement of the patch releases (ClamAV Blog). The Hacker News included the vulnerability in its weekly security recap, indicating moderate community awareness. Cisco PSIRT noted that several of the co-disclosed vulnerabilities were discovered through AI-assisted research tools, which drew some industry attention to the role of automated vulnerability discovery.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."