Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3139 articles · 183351 vulns · 37/41 feeds (7d)
← Back to list
7.5
CVE-2026-20213PATCHED
cis · secure_endpoint

ClamAV PE File Format Processing Out-of-Bounds Memory Corruption Vulnerability

Description

A vulnerability in the PE file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in PE files during scanning, which may result in an out-of-bounds buffer write. An attacker could exploit this vulnerability by submitting a crafted file that contains PE content to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.

Affected Products

VendorProductVersions
cissecure_endpoint7.0.5, 6.2.19, 7.3.3, 7.2.13, 6.1.5, 6.3.1, 6.2.5, 7.3.5, 6.2.1, 7.2.7, 7.1.1, 6.3.5, 6.2.9, 7.3.1, 6.1.7, 7.2.11, 7.2.3, 7.1.5, 6.3.3, 7.3.9, 6.2.3, 6.1.9, 6.0.9, 7.2.5, 6.0.7, 6.3.7, 1.12.3, 1.8.0, 1.11.1, 1.12.4, 1.10.0, 1.12.0, 1.8.1, 1.10.1, 1.12.1, 1.12.6, 1.14.0, 1.10.2, 1.12.7, 1.12.2, 1.6.0, 1.9.0, 1.11.0, 1.7.0, 1.13.0, 1.8.4, 1.13.1, 1.9.1, 1.12.5, 1.13.2, 8.1.7.21512, 8.1.7, 8.1.5, 8.1.3.21242, 8.1.3, 8.1.5.21322, 8.1.7.21417, 1.14.1, 1.15.1, 1.15.2, 1.15.3, 1.15.4, 1.15.5, 1.15.6, 1.16.0, 1.16.1, 1.16.2, 1.16.3, 1.18.0, 1.18.1, 1.20.0, 1.21.0, 1.21.1, 1.21.2, 1.21.3, 1.22.0, 1.22.1, 1.22.2, 1.22.3, 1.22.4, 1.24.0, 1.24.1, 1.24.2, 1.24.3, 1.24.4, 1.26.0, 1.24.5, 1.26.1, 1.27.0, 1.15.0, 1.17.0, 1.17.1, 1.17.2, 1.19.0, 1.20.1, 1.20.2, 1.20.3, 1.20.4, 1.20.5, 1.20.6, 1.23.0, 1.23.1, 1.20.7, 1.20.8, 1.25.0, 1.25.1, 1.25.2, 1.27.1, 1.27.2, 7.3.13, 7.3.15, 7.4.1, 7.4.1.20425, 7.4.1.20439, 7.4.3, 7.4.3.20679, 7.4.5, 7.5.1.20813, 7.5.1.20833, 7.5.3, 7.5.5, 8.0.1.21160, 8.0.1.21164, 7.5.7, 7.5.9, 7.5.11, 8.1.7.21585, 7.5.13.21586, 7.5.13.21598, 8.2.1.21612, 8.2.1.21650, 7.5.15.21611, 7.5.17.21680, 8.2.3.30119, 8.2.4.30130, 8.4.0, 7.5.19, 8.4.1.30298, 8.4.2.30317, 8.4.1.30307, 7.5.20, 8.4.3, 8.4.4.30419, 8.4.4.30467, 7.5.21.21732, 8.4.5.30483

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
clamavclamavcve_cpe95%
open sourceclamavcert_advisory90%

References

  • https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-88cFYyxR

Related News (5 articles)

Tier A
Microsoft MSRC23d ago
CVE-2026-20213 ClamAV PE File Format Processing Out-of-Bounds Memory Corruption Vulnerability
→ No new info (linked only)
Tier B
BSI Advisories32d ago
[NEU] [mittel] ClamAV: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
CERT-FR32d ago
Multiples vulnérabilités dans ClamAV (02 juillet 2026)
→ No new info (linked only)
Tier C
VulDB33d ago
CVE-2026-20213 | Cisco Secure Endpoint up to 8.4.5.30483 ClamAV buffer overflow (cisco-sa-clamav-88cFYyxR)
→ No new info (linked only)
Tier A
Cisco Security33d ago
ClamAV Vulnerabilities Affecting Cisco Products: July 2026
→ No new info (linked only)
CVSS 3.17.5 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
8.4.6
CWECWE-120
PublishedJul 1, 2026
Last enriched32d agov2
Trending Score5
Source articles5
Independent5
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

MEDIUMCVE-2026-20316
Cisco Secure Firewall Management Center Software Static Credential Vulnerability
Trending: 77
HIGHCVE-2026-20157
Cisco RoomOS Security Hardening Release - Missing Encryption Vulnerabilities
Trending: 6
HIGHCVE-2026-20244
ClamAV DMG File Processing Denial of Service Vulnerability
Trending: 6
HIGHCVE-2026-20216
ClamAV InstallShield File Format Processing Resource Exhaustion Vulnerability
Trending: 5
HIGHCVE-2026-20243
ClamAV ALZ Archive Processing Denial of Service Vulnerability
Trending: 5

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 1, 2026
Discovered by ZDM
Jul 1, 2026
Updated: severity, patchAvailable
Jul 1, 2026
Patch Available
Jul 1, 2026

Version History

v2
Last enriched 32d ago
v2Tier C32d ago

Updated severity to CRITICAL, noted no exploit available, and added patch version 8.4.6.

severitypatchAvailable
via VulDB
v133d ago

Initial creation