CVE-2026-20345 – Cisco Secure Endpoint

CVSS 7.5 IMPORTANT High with EoP or RCE – Expedited Deployment

“Crafted files can disrupt security scanning and expose vulnerable endpoints to memory corruption.”

Cisco Secure Endpoint is affected by seven high-severity ClamAV vulnerabilities involving ZIP, PESpin, GPT, PDF, Mach-O, and XAR file parsing. An unauthenticated remote attacker can submit crafted content for scanning and trigger memory handling or boundary-checking failures, causing the ClamAV scanning process to terminate and resulting in denial of service.

CVE-2026-20337, CVE-2026-20338, CVE-2026-20339, CVE-2026-20345, CVE-2026-20346, CVE-2026-20347, and CVE-2026-20348 each have a CVSS score of 7.5, High severity. Several flaws involve memory corruption conditions with potentially expanded impact.

Key Details

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
CWE Classification
CWE-121
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.