# ClamAV patches multiple vulnerabilities

Published: 2026-08-10 · Severity: elevated
Canonical: https://vorant.io/reports/91f38ddd-7102-573b-b892-804ca5c32036/clamav-patches-multiple-vulnerabilities

> ANSSI advisory details eight ClamAV vulnerabilities allowing data confidentiality breaches and denial of service, fixed in versions 1.5.4 and 1.4.6.

The French national cybersecurity agency (ANSSI/CERT-FR) issued an advisory covering multiple vulnerabilities in ClamAV, the widely-used open-source antivirus engine, affecting versions 1.5.x prior to 1.5.4 and all versions prior to 1.4.6. The vulnerabilities collectively enable an attacker to compromise data confidentiality, trigger denial-of-service conditions, and exploit an additional issue not further specified by the vendor.

Eight CVEs are referenced (CVE-2025-8088, CVE-2026-20337, CVE-2026-20338, CVE-2026-20339, CVE-2026-20345, CVE-2026-20346, CVE-2026-20347, CVE-2026-20348), tied to ClamAV's own security patch bulletin published August 7, 2026. No evidence of active exploitation is mentioned in the advisory; this is a standard vendor patch notification. Organizations running affected ClamAV versions should apply the vendor-supplied patches referenced in the ClamAV security bulletin.

## Mentioned in this report

- Vulnerabilities: CVE-2025-8088 (KEV), CVE-2026-20337, CVE-2026-20338, CVE-2026-20339, CVE-2026-20345, CVE-2026-20346, CVE-2026-20347, CVE-2026-20348

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0992

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/91f38ddd-7102-573b-b892-804ca5c32036/clamav-patches-multiple-vulnerabilities.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
