CVE-2026-20216

A vulnerability in the InstallShield file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper handling of temporary resources during file scanning. An attacker could exploit this vulnerability by submitting a crafted InstallShield file to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to terminate the ClamAV scanning process and temporarily consume available system resources, resulting in a DoS condition on the affected software.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:cisco:secure_endpoint:*:*:*:*:*:macos:*:*
cpe:2.3:a:cisco:secure_endpoint:*:*:*:*:*:linux:*:*
cpe:2.3:a:cisco:secure_endpoint:*:*:*:*:*:windows:*:*

Configuration 2 (hide)

OR cpe:2.3:a:clamav:clamav:*:*:*:*:*:*:*:*
cpe:2.3:a:clamav:clamav:*:*:*:*:*:*:*:*

History

09 Jul 2026, 18:09

Type Values Removed Values Added
References () https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-88cFYyxR - () https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-88cFYyxR - Vendor Advisory
First Time Cisco secure Endpoint
Cisco
Clamav clamav
Clamav
CPE cpe:2.3:a:cisco:secure_endpoint:*:*:*:*:*:windows:*:*
cpe:2.3:a:cisco:secure_endpoint:*:*:*:*:*:linux:*:*
cpe:2.3:a:cisco:secure_endpoint:*:*:*:*:*:macos:*:*
cpe:2.3:a:clamav:clamav:*:*:*:*:*:*:*:*

01 Jul 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-01 17:16

Updated : 2026-07-09 18:09


NVD link : CVE-2026-20216

Mitre link : CVE-2026-20216

CVE.ORG link : CVE-2026-20216


JSON object : View

Products Affected

clamav

  • clamav

cisco

  • secure_endpoint
CWE
CWE-770

Allocation of Resources Without Limits or Throttling