Canon Inc.
First CVE: May 11, 2023Active for: 3 years
48
CVEs Published
More CVEs Published than 56% of tracked CNAs
12.0
Avg CVEs / Year
More Avg CVEs / Year than 58% of tracked CNAs
8.4
Avg CVSS Score
Higher Avg CVSS Score than 93% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Self-Reporting Analysis
Of all the CVEs published by Canon Inc. as a CNA, 70.8% affect products that Canon Inc. develops as a vendor.
70.8%
29.2%
Self-reported: 34Third-party: 14
Of all the CVEs published that affect products developed by Canon Inc., 41.0% are self-published by Canon Inc. as a CNA.
41.0%
59.0%
Self-published: 34Published by other CNAs: 49
Trends Over Time
The number and severity of CVEs published by Canon Inc. over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 11, 2023
3 years ago
Most Recent CVE
Jun 16, 2026
38 days ago
Top CVEs
All CVEs published by Canon Inc. as a CNA, regardless of affected vendor or product.
48 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-9261CRITICAL Use of weak SSH cryptographic algorithms in Canon EOS Network Setting Tool Version 1.5.0 or earlier | Jun 16, 2026 | 9.8 | 36 | NO | NO |
CVE-2026-9260CRITICAL Use of hard-coded cryptographic keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier | Jun 16, 2026 | 9.8 | 34 | NO | NO |
CVE-2025-14236CRITICAL Buffer overflow in Address Book attribute tag processing on Small Office Multifunction Printers(*) which may allow an attacker on the network segment to trigger the affected produc | Jan 16, 2026 | 9.8 | 34 | NO | NO |
CVE-2025-14234CRITICAL Buffer overflow in CPCA list processing on Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected prod | Jan 16, 2026 | 9.8 | 34 | NO | NO |
CVE-2025-14231CRITICAL Buffer overflow in print job processing by WSD on Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affect | Jan 16, 2026 | 9.8 | 34 | NO | NO |
CVE-2026-9259CRITICAL Improper validation of server certificates in Canon EOS Network Setting Tool Version 1.5.0 or earlier | Jun 16, 2026 | 9.8 | 33 | NO | NO |
CVE-2026-9258CRITICAL Improper validation of SSH host keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier | Jun 16, 2026 | 9.8 | 33 | NO | NO |
CVE-2025-14237CRITICAL Buffer overflow in XPS font parse processing on Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected | Jan 16, 2026 | 9.8 | 33 | NO | NO |
CVE-2025-14233CRITICAL Invalid free in CPCA file deletion processing on Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affecte | Jan 16, 2026 | 9.8 | 32 | NO | NO |
CVE-2025-14232CRITICAL Buffer overflow in XML processing of XPS file in Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affecte | Jan 16, 2026 | 9.8 | 32 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA48 CVEs
29%
8%
63%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local3 (6.3%)
Network43 (89.6%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network2 (4.2%)
Attack Complexity
Low46 (95.8%)
High2 (4.2%)
Unknown0 (0.0%)
User Interaction
None44 (91.7%)
Unknown0 (0.0%)
Required4 (8.3%)
Privileges Required
Low2 (4.2%)
High4 (8.3%)
None42 (87.5%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (48 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by Canon Inc. as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Canon Inc. as a CNA — matched by CVE ID, not by organization name.