
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20346 is a memory corruption vulnerability in the PDF file format parser of ClamAV, classified as ClamAV PDF File Format Processing Memory Corruption. It allows an unauthenticated, remote attacker to cause a denial of service (DoS) condition — and potentially other expanded impacts — by submitting a crafted PDF file for scanning. The vulnerability affects ClamAV as bundled in Cisco Secure Endpoint Connector for Windows (prior to 8.6.3/7.5.24.21780), Linux (prior to 1.29.2), and Mac (prior to 1.27.4); Cisco Secure Endpoint Private Cloud is not directly affected. It was publicly disclosed on August 7, 2026, with a patch advisory updated through August 13, 2026. The CVSS v3.1 base score is 7.5 (High) (Cisco Advisory, GitHub Advisory).
The root cause is improper boundary checks when processing content in PDF files during ClamAV scanning, classified as CWE-125 (Out-of-bounds Read). When ClamAV parses a specially crafted PDF, it reads data beyond the intended buffer boundary, resulting in memory corruption that causes the scanning process to crash. The attack vector is network-based, requires no authentication, no privileges, and no user interaction — making it fully automatable. The vulnerability was reported by Tristan Madani from Talence Security and tracked under Cisco Bug ID CSCwu65985 (Cisco Advisory).
Successful exploitation terminates the ClamAV scanning process, resulting in a DoS condition that disrupts antivirus scanning operations on the affected device. On Windows-based platforms (Cisco Secure Endpoint Connector for Windows), the impact is rated High because ClamAV runs in a privileged security context, raising the potential for expanded impacts beyond DoS. On Linux and Mac platforms, the impact is rated Medium due to the lower-privileged execution context. There is no confirmed confidentiality or integrity impact at this time, though Cisco notes the possibility of "other expanded impacts as a result of memory corruption" (Cisco Advisory).
As of the advisory, Cisco PSIRT is not aware of proof-of-concept (PoC) exploit code specifically for CVE-2026-20346, nor any malicious exploitation in the wild. However, a Field Effect blog post published after the initial advisory indicates that public PoC code became available for related ClamAV vulnerabilities in this advisory batch (Field Effect Blog). The vulnerability is automatable (no user interaction required), which increases risk. The EPSS score is approximately 0.327% (26th percentile), and there is no current CISA KEV catalog listing for this CVE (GitHub Advisory).
clamd crash entries in /var/log/syslog or Windows Event Viewer); repeated scanning failures or error messages referencing PDF file processing.clamd or ClamAV scanning process without administrator action; automatic service restart events for ClamAV/Cisco Secure Endpoint Connector.Cisco has released fixed versions for all affected Secure Endpoint Connector platforms: Linux — version 1.29.2 (Bug ID CSCwv87285); Mac — version 1.27.4 (Bug ID CSCwv87286); Windows — version 8.6.3/7.5.24.21780 (Bug ID CSCwv87283). Updated connectors are available through the Cisco Secure Endpoint portal and may update automatically depending on configured policy. There are no workarounds available for this vulnerability. As a temporary measure until patching is possible, consider restricting PDF file submissions to ClamAV scanning or implementing additional input validation upstream. Cisco Secure Endpoint Private Cloud customers should monitor Bug ID CSCwv91588 for connector update availability (Cisco Advisory).
Cisco's PSIRT published the advisory on August 7, 2026, covering seven ClamAV vulnerabilities affecting Cisco Secure Endpoint, with CVE-2026-20346 among them. Security news outlets including GBHackers, CyberSecurityNews, and IT Security News covered the broader advisory, highlighting the risk of remote attackers crashing antivirus scanning with crafted files (GBHackers, CyberSecurityNews). Field Effect published a notable follow-up blog noting that public PoC code became available for some vulnerabilities in this advisory group (Field Effect Blog). The Hacker News included the ClamAV vulnerabilities in its weekly recap, and Linuxiac covered the ClamAV 1.5.4 release that addressed eight security vulnerabilities (Linuxiac).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."