• PoC PUBLIC

CVE-2026-20217: pre-auth denial of service in Cisco Cisco Secure Endpoint

Unauthenticated remote attackers can cause a denial-of-service or other memory-corruption impacts in Cisco Secure Endpoint by submitting a crafted PESpin file for scanning, exploiting a flaw in the embedded ClamAV PESpin parser (CVE-2026-20217). Affected builds include multiple 6.x and 7.x releases such as 6.1.5, 6.2.1, 6.2.5, 6.2.19, 6.3.1, 7.0.5, 7.2.7, 7.2.13, 7.3.3 and 7.3.5; no fixed releases are listed. An attacker only needs network access to submit a crafted file that will be scanned by the product to trigger the issue.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
7.5HIGH
EPSS
0.00573
CWE
CWE-120
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Urgent: public exploit code exists for this pre-auth memory-corruption bug, so prioritize mitigations for internet-facing scanning endpoints and apply vendor fixes immediately when released.

What is CVE-2026-20217?

Unauthenticated remote attackers can cause a denial-of-service or other memory-corruption impacts in Cisco Secure Endpoint by submitting a crafted PESpin file for scanning, exploiting a flaw in the embedded ClamAV PESpin parser (CVE-2026-20217). Affected builds include multiple 6.x and 7.x releases such as 6.1.5, 6.2.1, 6.2.5, 6.2.19, 6.3.1, 7.0.5, 7.2.7, 7.2.13, 7.3.3 and 7.3.5; no fixed releases are listed. An attacker only needs network access to submit a crafted file that will be scanned by the product to trigger the issue.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Which versions of Cisco Cisco Secure Endpoint are affected?

BRANCHAFFECTEDFIXED
7.x7.0.5
6.x6.2.19
7.x7.3.3
7.x7.2.13
6.x6.1.5
6.x6.3.1
6.x6.2.5
7.x7.3.5
6.x6.2.1
7.x7.2.7

Is CVE-2026-20217 being exploited?

Public exploit code is available for this vulnerability.

How to fix CVE-2026-20217

  1. Restrict exposure of any file-scanning interfaces to trusted networks and sources.
  2. Block or quarantine PESpin file types at perimeter controls where possible.
  3. Monitor Secure Endpoint and ClamAV processes for crashes and anomalous restarts and enable detailed logging of scan failures.
  4. Apply vendor updates or official workarounds as soon as Cisco releases a fixed build.

Frequently asked questions

Is CVE-2026-20217 being actively exploited?

Public exploit code is available for CVE-2026-20217; this indicates exploitation tools exist although a formal listing by CISA is not present as of 2026-09-29.

Which Cisco Secure Endpoint versions are affected by CVE-2026-20217?

Multiple 6.x and 7.x builds are listed as affected, including 6.1.5, 6.2.1, 6.2.5, 6.2.19, 6.3.1, 7.0.5, 7.2.7, 7.2.13, 7.3.3 and 7.3.5.

Is there a patch for CVE-2026-20217?

No fixed versions are listed in the available facts and no vendor patch is indicated as of 2026-09-29; follow Cisco guidance and apply fixes when published.

Does CVE-2026-20217 require authentication?

No — the vulnerability can be triggered by an unauthenticated remote submission of a crafted PESpin file that is scanned by the product.

References