
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20345 is a stack-based buffer overflow vulnerability in the GPT file format parser of ClamAV, classified as ClamAV GPT File Format Processing Memory Corruption. It allows an unauthenticated, remote attacker to cause a denial-of-service (DoS) condition or potentially other expanded impacts due to memory corruption. The vulnerability affects ClamAV as bundled with Cisco Secure Endpoint Connector for Windows (prior to 8.6.3/7.5.24.21780), Linux (prior to 1.29.2), and Mac (prior to 1.27.4). It was publicly disclosed on August 7, 2026, with a patch released on August 13, 2026. The CVSS v3.1 base score is 7.5 (High) (Cisco Advisory, GitHub Advisory).
The root cause is improper handling of an endian conversion operation in ClamAV's GPT file format parser, classified as CWE-121 (Stack-based Buffer Overflow). The flawed endian conversion can result in an out-of-bounds buffer write to the stack, leading to memory corruption. An attacker exploits this by submitting a specially crafted GPT (GUID Partition Table) file to a ClamAV-enabled scanning endpoint — no authentication or user interaction is required. CVE-2026-20345 was reported by researchers from the Atuin Automated Vulnerability Discovery Engine and Tianchu Chen of Tencent Xuanwu Lab (Cisco Advisory).
Successful exploitation causes the ClamAV scanning process to terminate, resulting in a DoS condition that disrupts antivirus scanning operations. On Windows-based platforms (Cisco Secure Endpoint Connector for Windows), the impact is rated High because ClamAV runs in a privileged security context, raising the risk of expanded impacts beyond DoS. On Linux and Mac platforms, the impact is rated Medium due to the lower-privileged execution context. There is no evidence of confidentiality or integrity impact at this time, but the advisory notes the possibility of "other expanded impacts" from the underlying memory corruption (Cisco Advisory).
No public proof-of-concept (PoC) exploit code is known for CVE-2026-20345 specifically; Cisco PSIRT confirmed PoC code exists only for CVE-2026-20337 and CVE-2026-20338 within the same advisory. There is no evidence of in-the-wild exploitation or threat actor attribution at this time. The EPSS score is approximately 0.327%, indicating a low near-term exploitation probability. The vulnerability is automatable (no user interaction required) and exploitable over the network without credentials, making it a candidate for opportunistic targeting if a PoC emerges (Cisco Advisory, GitHub Advisory).
clamd or Cisco Secure Endpoint scanning service) in system logs or application event logs; crash dump files generated by the ClamAV process.Cisco has released fixed versions to address this vulnerability: Secure Endpoint Connector for Windows version 8.6.3/7.5.24.21780, for Linux version 1.29.2, and for Mac version 1.27.4. Updated connectors are available through the Cisco Secure Endpoint portal and may update automatically depending on configured policy. There are no workarounds available; upgrading to a fixed release is the only remediation. As an interim measure until patching is complete, administrators should implement network controls to restrict GPT file submissions to ClamAV scanners or disable GPT file scanning if not operationally required (Cisco Advisory).
SecurityWeek reported on the broader set of ClamAV vulnerabilities disclosed in this advisory, noting that two of the seven flaws (CVE-2026-20337 and CVE-2026-20338) have public PoCs, which elevated community concern (SecurityWeek). Security Affairs and CyberSecurityNews also covered the advisory, highlighting the risk to Cisco Secure Endpoint installations (Security Affairs, CyberSecurityNews). Field Effect published a blog noting the availability of public PoC for related CVEs and advising prompt patching (Field Effect). The Linuxiac community noted the ClamAV 1.5.4 release addressing eight security vulnerabilities, including this flaw (Linuxiac).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."