
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20347 is a memory corruption vulnerability in the Mach-O file format parser of ClamAV, affecting Cisco Secure Endpoint Connector products. An unauthenticated, remote attacker can submit a crafted Mach-O file to trigger an out-of-bounds buffer read, potentially causing a denial of service (DoS) condition or other expanded impacts. The vulnerability was publicly disclosed on August 7, 2026, as part of a broader Cisco advisory covering seven ClamAV-related CVEs. It carries a CVSS v3.1 base score of 7.5 (High) (Cisco Advisory, GitHub Advisory).
The root cause is improper boundary checks (CWE-125: Out-of-bounds Read) when parsing content in Mach-O binary files during ClamAV scanning operations. When a specially crafted Mach-O file is submitted for scanning, the parser reads beyond the intended buffer boundary, resulting in memory corruption that can crash the scanning process. The attack vector is network-based, requires no authentication or user interaction, and has low attack complexity — an attacker simply needs to deliver a malicious file to a system where ClamAV will scan it. The vulnerability was reported by Tristan Madani from Talence Security (Cisco Advisory).
Successful exploitation causes the ClamAV scanning process to terminate, resulting in a denial of service condition that disrupts antivirus scanning operations on the affected device. On Windows-based platforms (Cisco Secure Endpoint Connector for Windows), the impact is rated High because ClamAV runs in a privileged security context, raising the potential for expanded impacts beyond DoS. On Linux and Mac platforms, the impact is rated Medium due to the lower-privileged execution context. There is no direct confidentiality or integrity impact confirmed, but the advisory notes the possibility of "other expanded impacts as a result of memory corruption" (Cisco Advisory).
As of the advisory's publication, Cisco PSIRT is not aware of any proof-of-concept exploit code specifically for CVE-2026-20347, nor any malicious exploitation in the wild. However, a Field Effect blog post published approximately ten days after disclosure noted that public PoC code became available for related ClamAV vulnerabilities in this advisory batch (Field Effect). The EPSS score is approximately 0.327%, indicating a low near-term exploitation probability. The vulnerability is automatable (no user interaction required), which lowers the barrier for opportunistic attacks. It has not been added to the CISA KEV catalog based on available information (GitHub Advisory).
clamd) in system logs (e.g., /var/log/syslog, Windows Event Log); crash reports or core dump files generated by the ClamAV process.clamd or ClamAV scanning process where it is expected to be running; repeated process restarts of the ClamAV daemon in a short time window..macho, or files with Mach-O magic bytes 0xFEEDFACE/0xFEEDFACF/0xCAFEBABE) in directories monitored by ClamAV, particularly from external or untrusted sources.Cisco has released fixed versions for all affected Secure Endpoint Connector platforms: 1.29.2 for Linux, 1.27.4 for Mac, and 8.6.3 (build 17.5.24.21780) for Windows (Cisco Advisory). Updated connectors are available through the Cisco Secure Endpoint portal and may auto-update depending on configured policy. Cisco confirms there are no workarounds available for this vulnerability. As interim risk reduction, organizations should implement network controls to restrict which sources can submit files to ClamAV for scanning and monitor the ClamAV service for unexpected terminations. Cisco Secure Endpoint Private Cloud is not directly affected but must push the fixed connector software to endpoints; Private Cloud releases 4.2.8 and later will support the fixed software (see CSCwv91588).
The vulnerability was covered by multiple security news outlets including GBHackers, CyberSecurityNews, and IT Security News, which highlighted the broader set of seven ClamAV vulnerabilities disclosed in the same Cisco advisory (GBHackers, CyberSecurityNews). Field Effect published a notable follow-up blog post indicating that public PoC code became available for some of the related ClamAV vulnerabilities in this advisory batch, raising the urgency for patching (Field Effect). The Hacker News included the ClamAV vulnerabilities in its weekly security recap, reflecting moderate community interest. The CISA vulnerability bulletin (SB26-222) also referenced the advisory, indicating government-level awareness.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."