CVE-2026-20347

Cisco · Cisco Secure Endpoint

A memory corruption vulnerability in the ClamAV Mach-O parser within Cisco Secure Endpoint allows unauthenticated remote attackers to trigger a denial of service condition.

Executive summary

A remote, unauthenticated denial of service vulnerability in Cisco Secure Endpoint, caused by improper Mach-O file parsing, poses a significant availability risk to protected systems.

Vulnerability

This vulnerability is an out-of-bounds read (CWE-125) within the ClamAV Mach-O file format parser. An unauthenticated remote attacker can trigger this flaw by sending a crafted Mach-O file to the target, resulting in memory corruption and a denial of service state.

Business impact

With a CVSS score of 7.5, this vulnerability represents a high risk to business continuity. Because it does not require authentication, attackers can remotely disable security features on targeted endpoints, effectively blinding the organization to other potential threats while the service is unavailable.

Remediation

Immediate Action: Consult the Cisco security advisory referenced in the metadata and apply the recommended software updates as soon as they become available.

Proactive Monitoring: Review security logs for anomalous file scan activity or repeated process failures within the Cisco Secure Endpoint service.

Compensating Controls: Utilize endpoint detection and response (EDR) tools to monitor for suspicious file-processing behavior and restrict incoming traffic from untrusted sources.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Organizations should treat this vulnerability as a high-priority item. Administrators must monitor for vendor-provided patches and apply them to all affected Cisco Secure Endpoint installations to maintain system integrity and availability.