Skip to content
VulniPulse
Medium5.3Cisco

Medium [CVE-2026-20031] ClamAV Cascading Style Sheets Image Parsing Error Handling Denial of Service Vulnerability

This medium-severity Cisco advisory covers CVE-2026-20031 affecting Cisco Secure Endpoint Private Cloud Console.

cisco-sa-clamav-css-Fn4QSZ Published Mar 4, 2026Updated by vendor Mar 4, 2026
Affected products & platforms
CiscoUnclassified
Open vendor advisory

Android app · Google Play

Monitor future Cisco CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

A vulnerability in the HTML Cascading Style Sheets (CSS) module of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper error handling when splitting UTF-8 strings.

An attacker could exploit this vulnerability by submitting a crafted HTML file to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to terminate the scanning process.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulne…

Affected product named by the advisory: Cisco Secure Endpoint Private Cloud Console.

Affected versions
  • Release Secure Endpoint Connector for Linux (first fixed: 1.28.11)
  • Release Secure Endpoint Connector for Mac (first fixed: 1.27.21)
  • Release Secure Endpoint Connector for Windows (first fixed: 8.6.01)
  • Release Secure Endpoint Private Cloud (first fixed: 4.2.7 or earlier with updated connectors2)

Official advisory · high-confidence parse· fetched 2 months ago·verify at source

Fixed versions
  • 1.28.11
  • 1.27.21
  • 8.6.01
  • 4.2.7 or earlier with updated connectors2

Official advisory · high-confidence parse· fetched 2 months ago·verify at source

Mitigation checklist

Recommended fix / mitigation
  • Upgrade to the first fixed release for your train per the Fixed Releases table in this advisory.
  • Release Secure Endpoint Connector for Linux: upgrade to 1.28.11.
  • Release Secure Endpoint Connector for Mac: upgrade to 1.27.21.
  • Release Secure Endpoint Connector for Windows: upgrade to 8.6.01.
  • Release Secure Endpoint Private Cloud: upgrade to 4.2.7 or earlier with updated connectors2.
Workaround status
  • There are no workarounds that address this vulnerability.

Official advisory · high-confidence parse· fetched 2 months ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.