New ClamAV security patch closes seven scanner bugs dating back two decades
PatchClamAVPE unpackerOur summary
Cisco Talos’ ClamAV released security patch versions 1.5.3 and 1.4.5 to address seven vulnerabilities affecting its executable and archive parsing logic, plus quarantine handling hardening. The fixes cover CVE-2026-20213, CVE-2026-20214, CVE-2026-20217, CVE-2026-20215, CVE-2026-20243, CVE-2026-20216, and CVE-2026-20244, which can lead to memory corruption, crashes, scanner bypass conditions, or unstable behavior when processing crafted inputs. These updates also matter because ClamAV is commonly used in mail gateways and endpoint/file scanning workflows where attackers may leverage malformed files to disrupt or evade scanning.
Help Net Security publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.