DIRAS TAKE
Urgent: public exploit code exists for this pre-auth memory-corruption bug, so prioritize mitigations for internet-facing scanning endpoints and apply vendor fixes immediately when released.
What is CVE-2026-20217?
Unauthenticated remote attackers can cause a denial-of-service or other memory-corruption impacts in Cisco Secure Endpoint by submitting a crafted PESpin file for scanning, exploiting a flaw in the embedded ClamAV PESpin parser (CVE-2026-20217). Affected builds include multiple 6.x and 7.x releases such as 6.1.5, 6.2.1, 6.2.5, 6.2.19, 6.3.1, 7.0.5, 7.2.7, 7.2.13, 7.3.3 and 7.3.5; no fixed releases are listed. An attacker only needs network access to submit a crafted file that will be scanned by the product to trigger the issue.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Which versions of Cisco Cisco Secure Endpoint are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 7.x | 7.0.5 | |
| 6.x | 6.2.19 | |
| 7.x | 7.3.3 | |
| 7.x | 7.2.13 | |
| 6.x | 6.1.5 | |
| 6.x | 6.3.1 | |
| 6.x | 6.2.5 | |
| 7.x | 7.3.5 | |
| 6.x | 6.2.1 | |
| 7.x | 7.2.7 |
Is CVE-2026-20217 being exploited?
Public exploit code is available for this vulnerability.
How to fix CVE-2026-20217
- Restrict exposure of any file-scanning interfaces to trusted networks and sources.
- Block or quarantine PESpin file types at perimeter controls where possible.
- Monitor Secure Endpoint and ClamAV processes for crashes and anomalous restarts and enable detailed logging of scan failures.
- Apply vendor updates or official workarounds as soon as Cisco releases a fixed build.
Frequently asked questions
Is CVE-2026-20217 being actively exploited?
Public exploit code is available for CVE-2026-20217; this indicates exploitation tools exist although a formal listing by CISA is not present as of 2026-09-29.
Which Cisco Secure Endpoint versions are affected by CVE-2026-20217?
Multiple 6.x and 7.x builds are listed as affected, including 6.1.5, 6.2.1, 6.2.5, 6.2.19, 6.3.1, 7.0.5, 7.2.7, 7.2.13, 7.3.3 and 7.3.5.
Is there a patch for CVE-2026-20217?
No fixed versions are listed in the available facts and no vendor patch is indicated as of 2026-09-29; follow Cisco guidance and apply fixes when published.
Does CVE-2026-20217 require authentication?
No — the vulnerability can be triggered by an unauthenticated remote submission of a crafted PESpin file that is scanned by the product.
References
- nvd.nist.gov/vuln/detail/CVE-2026-20217
- cve.org/CVERecord?id=CVE-2026-20217
- sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-88cFYyxR
- All Cisco CVEs on CVE Radar
- CVEs published in September 2026