Multiple vulnerabilities in ClamAV (August 10, 2026)
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
Multiple vulnerabilities were discovered in ClamAV. Some of them allow an attacker to cause compromise of data confidentiality, denial of service, and a security issue not specified by the vendor.
CSIRTS triage
- What
- Multiple vulnerabilities in ClamAV allow attackers to compromise data confidentiality, cause denial of service, and trigger unspecified security issues.
- Who is affected
- All ClamAV deployments are affected; specific versions not stated.
- Urgency
- Critical—multiple CVEs are actively exploited in the wild.
- Action
- Apply the latest ClamAV security update immediately.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch ClamAV
Get an email when a new ClamAV advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0992/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Exploitation confirmedCVE-2025-8088Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 99.9% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-203480.33% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 26% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-203470.33% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 26% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-203460.33% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 26% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-203450.33% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 26% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-203380.33% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 26% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-203370.36% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 29% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-203390.33% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 26% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2025-8088 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-20348 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-20347 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-20346 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-20345 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-20338 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-20337 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-20339 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] ClamAV: Multiple vulnerabilities allow Denial of Service and disclosure of informationcert-bund
- highClamAV Vulnerabilities Affecting Cisco Products: August 2026cisco-psirt
- unknownexploitedCisco Products Multiple Vulnerabilitieshkcert
- highCVE-2026-20347: ClamAV Mach-O File Format Processing Memory Corruption Vulnerabilitymsrc
- highCVE-2026-20345: ClamAV GPT File Format Processing Memory Corruption Vulnerabilitymsrc
- highCVE-2026-20348: ClamAV XAR File Format Processing Memory Corruption Vulnerabilitymsrc
- highCVE-2026-20338: ClamAV ZIP File Format Processing Memory Corruption Vulnerabilitymsrc
- highCVE-2026-20337: ClamAV ZIP File Format Processing Memory Corruption Vulnerabilitymsrc
- highCVE-2026-20339: ClamAV PESpin File Format Processing Integer Overflow Vulnerabilitymsrc
- highCVE-2026-20346: ClamAV PDF File Format Processing Memory Corruption Vulnerabilitymsrc
- highCVE-2026-20348: A vulnerability in the XAR file format parser of ClamAV could allow an unauthenticated, remote…nvd
- highCVE-2026-20347: A vulnerability in the Mach-O file format parser of ClamAV could allow an unauthenticated, rem…nvd
Recent advisories for ClamAV
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- high[UPDATE] [high] ClamAV: Multiple vulnerabilities enable Denial of Servicecert-bund · 2026-08-28
- high[NEW] [high] ClamAV: Multiple vulnerabilities allow Denial of Service and disclosure of informationcert-bund · 2026-08-18
- highClamAV Vulnerabilities Affecting Cisco Products: August 2026cisco-psirt · 2026-08-13
- highCVE-2026-20345: ClamAV GPT File Format Processing Memory Corruption Vulnerabilitymsrc · 2026-08-11
- highCVE-2026-20338: ClamAV ZIP File Format Processing Memory Corruption Vulnerabilitymsrc · 2026-08-11
- highCVE-2026-20346: ClamAV PDF File Format Processing Memory Corruption Vulnerabilitymsrc · 2026-08-11
More from CERT-FR Avis de sécurité
- unknownMultiples vulnérabilités dans le noyau Linux d'Ubuntu (04 septembre 2026)2026-09-04
- unknownMultiples vulnérabilités dans le noyau Linux de Red Hat (04 septembre 2026)2026-09-04
- unknownMultiples vulnérabilités dans le noyau Linux de Debian (04 septembre 2026)2026-09-04
- unknownMultiples vulnérabilités dans le noyau Linux de SUSE (04 septembre 2026)2026-09-04
- unknownMultiples vulnérabilités dans Elastic Kibana (04 septembre 2026)2026-09-04