Canon's vulnerability footprint spans a large portfolio of multifunction printers and imaging devices that are deeply embedded in enterprise office environments, presenting a significant but geographically distributed attack surface. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting the firmware and embedded-system nature of these devices and their network-facing management interfaces. The exposure concentrates in printer lines such as the LBP and MF series and recurs through critical weakness classes including out-of-bounds writes, stack-based buffer overflows, improper authentication mechanisms, and cross-site scripting in web administration panels—issues that can lead directly to device compromise, credential theft, or lateral movement into office networks. Defenders should treat Canon multifunction devices as security perimeters in their own right, inventory firmware versions across the fleet, and restrict management access to trusted networks; live severity, exploitation, and coverage counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Canon Inc. over time
Of all the CVEs published by Canon Inc. as a CNA, 70.8% affect products that Canon Inc. develops as a vendor.
Of all the CVEs published that affect products developed by Canon Inc., 41.0% are self-published by Canon Inc. as a CNA.
Signals from CVEs in this vendor scope (83 CVEs).
83 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-1185HIGH Unspecified vulnerability in Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via certain invalid HTML that causes memory corruption. | Apr 11, 2006 | 7.5 | 69 | NO | YES |
CVE-2006-1188HIGH Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via HTML elements with a certain crafted tag, which leads to memory corruption. | Apr 11, 2006 | 7.5 | 63 | NO | YES |
CVE-2021-38154HIGH Certain Canon devices manufactured in 2012 through 2020 (such as imageRUNNER ADVANCE iR-ADV C5250), when Catwalk Server is enabled for HTTP access, allow remote attackers to modify | Aug 29, 2021 | 7.5 | 37 | NO | YES |
CVE-2026-9261CRITICAL Use of weak SSH cryptographic algorithms in Canon EOS Network Setting Tool Version 1.5.0 or earlier | Jun 16, 2026 | 9.8 | 36 | NO | NO |
CVE-2026-9260CRITICAL Use of hard-coded cryptographic keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier | Jun 16, 2026 | 9.8 | 34 | NO | NO |
CVE-2025-14236CRITICAL Buffer overflow in Address Book attribute tag processing on Small Office Multifunction Printers(*) which may allow an attacker on the network segment to trigger the affected produc | Jan 16, 2026 | 9.8 | 34 | NO | NO |
CVE-2025-14234CRITICAL Buffer overflow in CPCA list processing on Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected prod | Jan 16, 2026 | 9.8 | 34 | NO | NO |
CVE-2025-14231CRITICAL Buffer overflow in print job processing by WSD on Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affect | Jan 16, 2026 | 9.8 | 34 | NO | NO |
CVE-2021-38085HIGH The Canon TR150 print driver through 3.71.2.10 is vulnerable to a privilege escalation issue. During the add printer process, a local attacker can overwrite CNMurGE.dll and, if tim | Aug 11, 2021 | 7.8 | 34 | NO | YES |
CVE-2026-9259CRITICAL Improper validation of server certificates in Canon EOS Network Setting Tool Version 1.5.0 or earlier | Jun 16, 2026 | 9.8 | 33 | NO | NO |
Signals from CVEs in this vendor scope (83 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Canon Inc..
Media articles that mention a CVE ID that affects a product developed by Canon Inc. — matched by CVE ID, not by vendor name.