ClamAV released security patch versions 1.5.4 and 1.4.6 to fix seven vulnerabilities in the antivirus engine, along with additional stability issues affecting archive, partition, PDF, Mach-O, and PE parsing. The updates also incorporate an upstream UnRAR fix for CVE-2025-8088, resolve thread-safety problems in the clamd STATS command that could leak memory or crash the daemon, restore safe quarantine behavior on FreeBSD, and in 1.5.4 fix an OpenSSL library-context leak in legacy hashing helpers. Both releases also update the Rust crossbeam-epoch dependency to remediate RUSTSEC-2026-0204.
Advisories highlighted CVE-2026-20337 and CVE-2026-20338 as high-severity ZIP archive parser denial-of-service flaws caused by improper input validation during scanning, with public proof-of-concept code reportedly available. An unauthenticated remote attacker could submit crafted archives to disrupt scanning operations and affect service availability. Affected versions include ClamAV 1.5.x before 1.5.4 and 1.4.x before 1.4.6, while Cisco said related fixes also apply to Secure Endpoint Connector for Windows, Linux, and macOS and to Private Cloud 4.2.x before 4.2.8, with updated connector builds being released through August.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
ClamAV released versions 1.5.4 and 1.4.6 to remediate multiple vulnerabilities and stability issues, including seven CVEs in ClamAV itself, an upstream UnRAR fix for CVE-2025-8088, clamd STATS thread-safety flaws, and a FreeBSD quarantine fix.
Cisco released security updates addressing seven high-severity ClamAV vulnerabilities affecting ClamAV-based products, and highlighted that public proof-of-concept code exists for CVE-2026-20337 and CVE-2026-20338. The notice says affected products include ClamAV before 1.5.4 and 1.4.6, Secure Endpoint Connector builds before the August 2026 release, and Private Cloud 4.2.x before 4.2.8.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
12 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourcescworld.com
Open sourcesecurityaffairs.com
Open sourcebleepingcomputer.com
Open sourcesecurityweek.com
Open sourceacn.gov.it
Open sourceblog.clamav.net
Open sourcecisa.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.