ClamAV patches multiple vulnerabilities
ANSSI advisory details eight ClamAV vulnerabilities allowing data confidentiality breaches and denial of service, fixed in versions 1.5.4 and 1.4.6.
The French national cybersecurity agency (ANSSI/CERT-FR) issued an advisory covering multiple vulnerabilities in ClamAV, the widely-used open-source antivirus engine, affecting versions 1.5.x prior to 1.5.4 and all versions prior to 1.4.6. The vulnerabilities collectively enable an attacker to compromise data confidentiality, trigger denial-of-service conditions, and exploit an additional issue not further specified by the vendor.
Eight CVEs are referenced (CVE-2025-8088, CVE-2026-20337, CVE-2026-20338, CVE-2026-20339, CVE-2026-20345, CVE-2026-20346, CVE-2026-20347, CVE-2026-20348), tied to ClamAV's own security patch bulletin published August 7, 2026. No evidence of active exploitation is mentioned in the advisory; this is a standard vendor patch notification. Organizations running affected ClamAV versions should apply the vendor-supplied patches referenced in the ClamAV security bulletin.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0992
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free