CVE Tools

New ClamAV security patch closes seven scanner bugs dating back two decades

Help Net SecurityBy Sinisa Markovic

PatchClamAVPE unpacker

Our summary

Cisco Talos’ ClamAV released security patch versions 1.5.3 and 1.4.5 to address seven vulnerabilities affecting its executable and archive parsing logic, plus quarantine handling hardening. The fixes cover CVE-2026-20213, CVE-2026-20214, CVE-2026-20217, CVE-2026-20215, CVE-2026-20243, CVE-2026-20216, and CVE-2026-20244, which can lead to memory corruption, crashes, scanner bypass conditions, or unstable behavior when processing crafted inputs. These updates also matter because ClamAV is commonly used in mail gateways and endpoint/file scanning workflows where attackers may leverage malformed files to disrupt or evade scanning.

Read at Help Net Security

Help Net Security publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store