Multiple vulnerabilities in ClamAV (August 10, 2026)
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
Multiple vulnerabilities were discovered in ClamAV. Some of them allow an attacker to cause compromise of data confidentiality, denial of service, and a security issue not specified by the vendor.
CSIRTS triage
- What
- Multiple vulnerabilities in ClamAV allow attackers to compromise data confidentiality, cause denial of service, and trigger unspecified security issues.
- Who is affected
- All ClamAV deployments are affected; specific versions not stated.
- Urgency
- Critical—multiple CVEs are actively exploited in the wild.
- Action
- Apply the latest ClamAV security update immediately.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch ClamAV
Get an email when a new ClamAV advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0992/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Exploitation confirmedCVE-2025-8088Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 99.8% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-203480.33% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 26% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-203470.33% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 26% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-203460.33% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 26% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-203450.33% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 26% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-203380.33% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 26% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-203370.36% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 29% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-203390.33% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 26% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2025-8088 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-20348 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-20347 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-20346 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-20345 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-20338 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-20337 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-20339 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- highClamAV Vulnerabilities Affecting Cisco Products: August 2026cisco-psirt
- unknownexploitedCisco Products Multiple Vulnerabilitieshkcert
- high[NEW] [high] ClamAV: Multiple vulnerabilities allow Denial of Service and disclosure of informationcert-bund
- highCVE-2026-20338: ClamAV ZIP File Format Processing Memory Corruption Vulnerabilitymsrc
- highCVE-2026-20345: ClamAV GPT File Format Processing Memory Corruption Vulnerabilitymsrc
- highCVE-2026-20339: ClamAV PESpin File Format Processing Integer Overflow Vulnerabilitymsrc
- highCVE-2026-20347: ClamAV Mach-O File Format Processing Memory Corruption Vulnerabilitymsrc
- highCVE-2026-20348: ClamAV XAR File Format Processing Memory Corruption Vulnerabilitymsrc
- highCVE-2026-20346: ClamAV PDF File Format Processing Memory Corruption Vulnerabilitymsrc
- highCVE-2026-20337: ClamAV ZIP File Format Processing Memory Corruption Vulnerabilitymsrc
- highCVE-2026-20348: A vulnerability in the XAR file format parser of ClamAV could allow an unauthenticated, remote…nvd
- highCVE-2026-20347: A vulnerability in the Mach-O file format parser of ClamAV could allow an unauthenticated, rem…nvd
Recent advisories for ClamAV
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- highClamAV Vulnerabilities Affecting Cisco Products: August 2026cisco-psirt · 2026-08-13
- high[NEW] [high] ClamAV: Multiple vulnerabilities allow Denial of Service and disclosure of informationcert-bund · 2026-08-11
- highCVE-2026-20347: ClamAV Mach-O File Format Processing Memory Corruption Vulnerabilitymsrc · 2026-08-11
- highCVE-2026-20337: ClamAV ZIP File Format Processing Memory Corruption Vulnerabilitymsrc · 2026-08-11
- highCVE-2026-20338: ClamAV ZIP File Format Processing Memory Corruption Vulnerabilitymsrc · 2026-08-11
- highCVE-2026-20345: ClamAV GPT File Format Processing Memory Corruption Vulnerabilitymsrc · 2026-08-11
More from CERT-FR Avis de sécurité
- unknownMultiple vulnerabilities in Elastic Kibana (August 14, 2026)2026-08-14
- unknownMultiple vulnerabilities in Netgate products (August 14, 2026)2026-08-14
- unknownMultiple vulnerabilities in SUSE Linux kernel (August 14, 2026)2026-08-14
- unknownMultiple vulnerabilities in Stormshield Network Security (August 14, 2026)2026-08-14
- unknownVulnerability in Sophos products (August 14, 2026)2026-08-14