PatchDayAlert
Daily Digest · 2 min read · 5 CVEs · Issue 75 By PatchDayAlert

ClamAV gets 4 parser bugs at once, plus a Plesk SQL injection worth watching

Cisco dropped 4 ClamAV crashes (all CVSS 7.5, no auth required) across XAR, Mach-O, GPT, and PESpin parsers, some with code execution potential. Plesk Obsidian also has a 7.7 authenticated SQL injection that exposes the entire panel database.

Patch now
0
Within 24h
1
This week
4
Exploited
0
Plesk ObsidianLinuxWindowsClamAVCiscoMacOS

Light day, nothing exploited in the wild, but don't sleep on it. A SQL injection in Plesk Obsidian (CVE-2026-64636, CVSS 7.7) lets any authenticated user dump the entire panel database, credentials included. If you run shared hosting with customer Plesk logins, patch that first, then deal with 4 ClamAV parser bugs that can crash your scanners with zero authentication.


Today's CVEs

Sorted by urgency

02

CVE-2026-20348

NVD
7.5
CVSS EPSS 0.33%
Patch this week HIGH
ClamAVCiscoLinuxWindows

An attacker can crash the ClamAV scanning process by sending a specially crafted XAR archive. The bug is a memory corruption issue triggered during XAR file parsing, and Cisco notes it could potentially go beyond a simple crash. No authentication is needed: just get the malicious file in front of a ClamAV scanner, for example through an email gateway or file upload endpoint.

Affected estate
Anyone running ClamAV for mail gateway scanning, file upload inspection, or endpoint protection
How to check
Run 'clamscan --version' or 'clamd --version' and compare against the fixed version listed in Cisco's advisory.
Included because
unauthenticated; remotely triggerable via email or file upload; memory corruption with possible expanded impact
Action
Update ClamAV to the patched version via your package manager or Cisco's download.
Why it matters
A crashed scanner means mail or file uploads go unscanned, creating a gap attackers can walk through.
Source
Cisco Security Advisory

Evidence trail

03

CVE-2026-20347

NVD
7.5
CVSS EPSS 0.33%
Patch this week HIGH
ClamAVCiscoLinuxWindowsMacOS

ClamAV's Mach-O file parser has an out-of-bounds read that lets an attacker crash the scanning process with a crafted file. No authentication required. While the primary impact is denial of service, Cisco flags the potential for broader memory corruption consequences. Any path that feeds files into ClamAV is an attack surface here.

Affected estate
Anyone running ClamAV for mail gateway scanning, file upload inspection, or endpoint protection
How to check
Run 'clamscan --version' and compare against the fixed version in Cisco's advisory.
Included because
unauthenticated; remotely triggerable; memory corruption with possible expanded impact
Action
Update ClamAV to the patched version via your package manager or Cisco's download.
Why it matters
A killed scanner process leaves a gap in your antimalware pipeline until the service restarts or is noticed.
Source
Cisco Security Advisory

Evidence trail

04

CVE-2026-20345

NVD
7.5
CVSS EPSS 0.33%
Patch this week HIGH
ClamAVCiscoLinuxWindows

ClamAV's GPT disk image parser has a bug in an endian conversion operation that can cause an out-of-bounds buffer write. Sending a crafted GPT image to ClamAV crashes the scanner, and the write primitive means code execution may be possible. No authentication needed: just deliver the file via email, upload, or any other scanned channel.

Affected estate
Anyone running ClamAV for mail gateway scanning, file upload inspection, or endpoint protection
How to check
Run 'clamscan --version' and compare against the fixed version listed in Cisco's advisory.
Included because
unauthenticated; remotely triggerable; out-of-bounds write with possible code execution
Action
Update ClamAV to the patched version via your package manager or Cisco's download.
Why it matters
An out-of-bounds write is more dangerous than a simple crash. This could potentially be chained into code execution on your scanning host.
Source
Cisco Security Advisory

Evidence trail

05

CVE-2026-20339

NVD
7.5
CVSS EPSS 0.33%
Patch this week HIGH
ClamAVCiscoLinuxWindows

ClamAV's PESpin parser has an integer overflow triggered by crafted PESpin-packed content. An attacker can crash the ClamAV process by submitting a malicious file, and memory corruption opens the door to potentially worse outcomes. No authentication is required, so any file intake path is a viable attack vector.

Affected estate
Anyone running ClamAV for mail gateway scanning, file upload inspection, or endpoint protection
How to check
Run 'clamscan --version' and compare against the fixed version in Cisco's advisory.
Included because
unauthenticated; remotely triggerable; integer overflow leading to memory corruption
Action
Update ClamAV to the patched version via your package manager or Cisco's download.
Why it matters
A downed antimalware scanner on your mail gateway or upload service means malicious files pass through unchecked.
Source
Cisco Security Advisory

Evidence trail


One email, every Wednesday morning.

Subscribe