📣 Send us your press release
Site updates every 15 minutes
Technology

Critical Security Vulnerabilities Found in Cisco's ClamAV Antivirus Scanner

Multiple critical vulnerabilities in Cisco's ClamAV antivirus scanner allow attackers to cause denial-of-service conditions and potentially execute malicious code, leading to system compromise.

9 October 2026
Critical Security Vulnerabilities Found in Cisco's ClamAV Antivirus Scanner

Several critical security vulnerabilities have been discovered in the ClamAV antivirus engine, owned by Cisco. Attackers can exploit these flaws to remotely trigger denial-of-service (DoS) attacks without authentication, causing the scanner to crash. In one instance, malicious code execution is also possible on Windows systems.

The vulnerabilities, seven of which enable DoS attacks and one allowing for code execution when processing RAR archives on Windows, are classified as "high" severity. These flaws can be triggered by attackers submitting specially crafted files, such as ZIP archives or PDFs, for the scanner to process.

Cisco has released security patches in versions 1.4.6 and 1.5.4 to address the eight identified vulnerabilities. While Cisco has not reported active exploitation of these flaws, proof-of-concept code is circulating for some of them, indicating a potential for imminent attacks. An updated version for Cisco Secure Endpoint Connector is also expected this month.

Given ClamAV's role in protecting mail servers and gateways, these vulnerabilities pose a significant risk. System administrators are strongly advised to apply the available security patches promptly to mitigate potential threats and ensure the integrity of their systems.

Original source: heise.de