
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20339 is a ClamAV PESpin File Format Processing Integer Overflow vulnerability that allows an unauthenticated, remote attacker to cause a denial of service (DoS) condition or potentially other expanded impacts due to memory corruption. The flaw resides in the PESpin file format parser and affects Cisco Secure Endpoint Connector for Windows (prior to 8.6.3), Linux (prior to 1.29.2), and Mac (prior to 1.27.4). It was publicly disclosed on August 7, 2026, and was reported by researchers Feng Xue and Yazdan Soltani. The vulnerability carries a CVSS v3.1 base score of 7.5 (High) (Cisco Advisory, GitHub Advisory).
The root cause is improper boundary checks when processing PESpin-formatted file content during ClamAV scanning, classified as CWE-190 (Integer Overflow or Wraparound). When ClamAV parses a crafted PESpin file, an integer overflow can occur, leading to memory corruption that causes the scanning process to terminate abnormally. The attack vector is network-based, requires no authentication, no user interaction, and no special privileges — making it fully automatable. On Windows platforms, the ClamAV scanning process runs in a privileged security context, elevating the Security Impact Rating (SIR) to High; on Linux and Mac, the process runs with lower privileges, resulting in a Medium SIR (Cisco Advisory).
Successful exploitation causes the ClamAV scanning process to terminate, resulting in a DoS condition that disrupts malware detection capabilities on the affected endpoint. On Windows-based Cisco Secure Endpoint Connectors, the elevated privilege context of the scanning process increases the potential for expanded impacts beyond DoS, including possible memory corruption effects. There is no confirmed confidentiality or integrity impact at this time, but Cisco's advisory notes the possibility of "other expanded impacts" beyond DoS (Cisco Advisory, GitHub Advisory).
As of the disclosure date, Cisco PSIRT confirmed there is no known proof-of-concept (PoC) exploit code specifically for CVE-2026-20339, and no evidence of malicious exploitation in the wild. Note that PoC code does exist for two related vulnerabilities in the same advisory (CVE-2026-20337 and CVE-2026-20338), which may lower the barrier for researchers to develop exploits for CVE-2026-20339. The EPSS score is approximately 0.327%, indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA KEV catalog, and NVD's SSVC assessment classifies exploitation as "none" with automatable attack potential (Cisco Advisory, GitHub Advisory).
clamd, clamscan, or the Cisco Secure Endpoint Connector scanning service); repeated process restarts in a short time window.Cisco has released fixed versions to address this vulnerability: Secure Endpoint Connector for Windows version 8.6.3 (build 17.5.24.21780), Secure Endpoint Connector for Linux version 1.29.2, and Secure Endpoint Connector for Mac version 1.27.4. There are no workarounds available — upgrading to a fixed release is the only remediation. Depending on the configured policy, Cisco Secure Endpoint Connector may automatically update; customers using Secure Endpoint Private Cloud should monitor Cisco Bug ID CSCwv91588 for connector repository update availability. As an interim measure, administrators can restrict file submission to ClamAV scanning services to trusted sources and monitor ClamAV process availability (Cisco Advisory).
Security Week reported on the broader set of seven ClamAV vulnerabilities disclosed in this advisory, highlighting that two related flaws (CVE-2026-20337 and CVE-2026-20338) have public PoC code available, which drew significant community attention. Security Affairs and CyberSecurityNews also covered the advisory, noting the risk to Cisco Secure Endpoint installations. Field Effect published a blog post specifically noting the availability of public PoCs for the related ClamAV vulnerabilities, urging prompt patching. The CISA Vulnerability Bulletin (SB26-222) included this CVE in its weekly summary, and the advisory was discussed on Mastodon and Infosec.Exchange by security researchers (SecurityWeek, Security Affairs, Field Effect).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."