Summary
Cisco reports seven high-severity vulnerabilities in the ClamAV engine that allow unauthenticated attackers to cause denial-of-service conditions. The flaws affect various file parsers and have public exploit code available for ZIP-related vulnerabilities.
Take Action:
If you run ClamAV or the Cisco Secure Endpoint Connector on Windows, Linux, or Mac, update ClamAV to version 1.5.4 now and watch the Cisco Secure Endpoint portal for the Connector updates coming later in August 2026. Until you have patched, keep an eye out for the antivirus service unexpectedly stopping. That may be a sign of an attack, and any machine in that state is unprotected and should be checked for other malware.
Read the full article on BeyondMachines
This article was originally published on BeyondMachines
Top comments (0)