Cisco Warns of Seven ClamAV Flaws, Two With Public PoCs
Cisco warns of seven ClamAV denial-of-service flaws in Secure Endpoint Connector, two with public PoCs; patches due in August.
Cisco warned that seven ClamAV denial-of-service vulnerabilities, tracked as CVE-2026-20337 through CVE-2026-20339 and CVE-2026-20345 through CVE-2026-20348, affect the Secure Endpoint Connector on Windows, macOS and Linux. Two flaws, CVE-2026-20337 (CVSS 7.5, out-of-bounds write) and CVE-2026-20338 (memory double-free), have public proof-of-concept code, but Cisco PSIRT reports no evidence of malicious exploitation. Fixes shipped in ClamAV 1.5.4, with Cisco patches due in August and no workaround available. Windows is rated high risk because ClamAV runs with elevated privileges there.
Cisco security advisory (AV26-876)
Canada's Cyber Centre relayed Cisco advisories covering a Nexus 9000 Silicon One RCE, IOS XR hardening, and denial-of-service flaws across IP phone lines.
The Canadian Centre for Cyber Security advisory AV26-876 lists Cisco vulnerabilities affecting IOS XR, Nexus 9000 Series switches, and several IP phone series. Included are a Nexus 9000 Silicon One remote code execution vulnerability, a September 2026 IOS XR security hardening release, and SIP software denial-of-service flaws in Desk Phone 9800, IP Phone 7800/8800, and Video Phone 8875. The Cyber Centre urges users and administrators to review the Cisco advisories and apply updates as they become available. No active exploitation is reported in the advisory.
Cisco Packaged Contact Center Enterprise and Cisco Unified Contact Center Enterprise Server-Side Request Forgery Vulnerability
Cisco patched an authenticated SSRF flaw in Packaged CCE and Unified CCE that lets credentialed users send arbitrary network requests from affected devices.
A server-side request forgery vulnerability caused by improper input validation of specific HTTP requests affects Cisco Packaged Contact Center Enterprise and Cisco Unified Contact Center Enterprise. An authenticated, remote attacker with valid user credentials can send crafted HTTP requests to make the device issue arbitrary network requests. Cisco has released software updates; no exploitation is reported in the advisory.