CVE-2026-20347
Clam AntiVirus vulnerability analysis and mitigation

Overview

CVE-2026-20347 is a memory corruption vulnerability in the Mach-O file format parser of ClamAV, affecting Cisco Secure Endpoint Connector products. An unauthenticated, remote attacker can submit a crafted Mach-O file to trigger an out-of-bounds buffer read, potentially causing a denial of service (DoS) condition or other expanded impacts. The vulnerability was publicly disclosed on August 7, 2026, as part of a broader Cisco advisory covering seven ClamAV-related CVEs. It carries a CVSS v3.1 base score of 7.5 (High) (Cisco Advisory, GitHub Advisory).

Technical details

The root cause is improper boundary checks (CWE-125: Out-of-bounds Read) when parsing content in Mach-O binary files during ClamAV scanning operations. When a specially crafted Mach-O file is submitted for scanning, the parser reads beyond the intended buffer boundary, resulting in memory corruption that can crash the scanning process. The attack vector is network-based, requires no authentication or user interaction, and has low attack complexity — an attacker simply needs to deliver a malicious file to a system where ClamAV will scan it. The vulnerability was reported by Tristan Madani from Talence Security (Cisco Advisory).

Impact

Successful exploitation causes the ClamAV scanning process to terminate, resulting in a denial of service condition that disrupts antivirus scanning operations on the affected device. On Windows-based platforms (Cisco Secure Endpoint Connector for Windows), the impact is rated High because ClamAV runs in a privileged security context, raising the potential for expanded impacts beyond DoS. On Linux and Mac platforms, the impact is rated Medium due to the lower-privileged execution context. There is no direct confidentiality or integrity impact confirmed, but the advisory notes the possibility of "other expanded impacts as a result of memory corruption" (Cisco Advisory).

Exploitability

As of the advisory's publication, Cisco PSIRT is not aware of any proof-of-concept exploit code specifically for CVE-2026-20347, nor any malicious exploitation in the wild. However, a Field Effect blog post published approximately ten days after disclosure noted that public PoC code became available for related ClamAV vulnerabilities in this advisory batch (Field Effect). The EPSS score is approximately 0.327%, indicating a low near-term exploitation probability. The vulnerability is automatable (no user interaction required), which lowers the barrier for opportunistic attacks. It has not been added to the CISA KEV catalog based on available information (GitHub Advisory).

Exploitation steps

  1. Identify target: Locate systems running Cisco Secure Endpoint Connector (Windows, Linux, or Mac) with an unpatched ClamAV version that scans files from external or untrusted sources.
  2. Craft malicious Mach-O file: Create a specially crafted Mach-O binary with malformed content that violates boundary checks in ClamAV's Mach-O parser, triggering an out-of-bounds read.
  3. Deliver the file: Submit the crafted Mach-O file to the target system through any channel that causes ClamAV to scan it — such as email attachment, file upload to a shared directory, web download, or direct submission to a ClamAV scanning service endpoint.
  4. Trigger the vulnerability: When ClamAV processes the malicious file, the Mach-O parser reads beyond the intended buffer boundary, causing memory corruption.
  5. Achieve DoS: The ClamAV scanning process crashes and terminates, disabling antivirus scanning on the affected host and potentially enabling subsequent malicious files to go undetected (Cisco Advisory).

Indicators of compromise

  • Logs: Unexpected termination entries for the ClamAV scanning process (clamd) in system logs (e.g., /var/log/syslog, Windows Event Log); crash reports or core dump files generated by the ClamAV process.
  • Process: Sudden absence of the clamd or ClamAV scanning process where it is expected to be running; repeated process restarts of the ClamAV daemon in a short time window.
  • File System: Presence of unusual Mach-O binary files (.macho, or files with Mach-O magic bytes 0xFEEDFACE/0xFEEDFACF/0xCAFEBABE) in directories monitored by ClamAV, particularly from external or untrusted sources.
  • Network: Inbound file transfers containing Mach-O content to systems where ClamAV is deployed for scanning, especially from unexpected or external sources.

Mitigation and workarounds

Cisco has released fixed versions for all affected Secure Endpoint Connector platforms: 1.29.2 for Linux, 1.27.4 for Mac, and 8.6.3 (build 17.5.24.21780) for Windows (Cisco Advisory). Updated connectors are available through the Cisco Secure Endpoint portal and may auto-update depending on configured policy. Cisco confirms there are no workarounds available for this vulnerability. As interim risk reduction, organizations should implement network controls to restrict which sources can submit files to ClamAV for scanning and monitor the ClamAV service for unexpected terminations. Cisco Secure Endpoint Private Cloud is not directly affected but must push the fixed connector software to endpoints; Private Cloud releases 4.2.8 and later will support the fixed software (see CSCwv91588).

Community reactions

The vulnerability was covered by multiple security news outlets including GBHackers, CyberSecurityNews, and IT Security News, which highlighted the broader set of seven ClamAV vulnerabilities disclosed in the same Cisco advisory (GBHackers, CyberSecurityNews). Field Effect published a notable follow-up blog post indicating that public PoC code became available for some of the related ClamAV vulnerabilities in this advisory batch, raising the urgency for patching (Field Effect). The Hacker News included the ClamAV vulnerabilities in its weekly security recap, reflecting moderate community interest. The CISA vulnerability bulletin (SB26-222) also referenced the advisory, indicating government-level awareness.

Additional resources


SourceThis report was generated using AI

Related Clam AntiVirus vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-20348HIGH7.5
  • Clam AntiVirus logoClam AntiVirus
  • clamav1.4
NoYesAug 07, 2026
CVE-2026-20347HIGH7.5
  • Clam AntiVirus logoClam AntiVirus
  • clamav
NoYesAug 07, 2026
CVE-2026-20346HIGH7.5
  • Clam AntiVirus logoClam AntiVirus
  • clamav
NoYesAug 07, 2026
CVE-2026-20345HIGH7.5
  • Clam AntiVirus logoClam AntiVirus
  • clamav
NoYesAug 07, 2026
CVE-2026-70622HIGH7.1
  • Clam AntiVirus logoClam AntiVirus
  • rust-cargo-c
NoNoAug 10, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management