CVE-2026-20345 – Cisco Secure Endpoint
CVSS 7.5
IMPORTANT
High with EoP or RCE – Expedited Deployment
“Crafted files can disrupt security scanning and expose vulnerable endpoints to memory corruption.”
Cisco Secure Endpoint is affected by seven high-severity ClamAV vulnerabilities involving ZIP, PESpin, GPT, PDF, Mach-O, and XAR file parsing. An unauthenticated remote attacker can submit crafted content for scanning and trigger memory handling or boundary-checking failures, causing the ClamAV scanning process to terminate and resulting in denial of service.
CVE-2026-20337, CVE-2026-20338, CVE-2026-20339, CVE-2026-20345, CVE-2026-20346, CVE-2026-20347, and CVE-2026-20348 each have a CVSS score of 7.5, High severity. Several flaws involve memory corruption conditions with potentially expanded impact.
Key Details
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- None
- CWE Classification
- CWE-121
Patch this CVE on all your endpoints in under 5 minutes.
First 200 endpoints are free forever, scale as needed.