Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Canon Inc.

First CVE: Dec 31, 2004Active for: 22 yearsTotal CVEs: 83
53.0
VTI Score
TOP TARGET

Canon's vulnerability footprint spans a large portfolio of multifunction printers and imaging devices that are deeply embedded in enterprise office environments, presenting a significant but geographically distributed attack surface. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting the firmware and embedded-system nature of these devices and their network-facing management interfaces. The exposure concentrates in printer lines such as the LBP and MF series and recurs through critical weakness classes including out-of-bounds writes, stack-based buffer overflows, improper authentication mechanisms, and cross-site scripting in web administration panels—issues that can lead directly to device compromise, credential theft, or lateral movement into office networks. Defenders should treat Canon multifunction devices as security perimeters in their own right, inventory firmware versions across the fleet, and restrict management access to trusted networks; live severity, exploitation, and coverage counts are shown alongside this summary.

FAUCET AI Generated
83
Total CVEs
More Total CVEs than 99% of tracked vendors
0.0
Avg CVEs / Product / Year
Bottom 1%
8.0
Avg CVSS Score
Higher Avg CVSS Score than 77% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Canon Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2004
21 years ago
Most Recent CVE
Jun 16, 2026
38 days ago

Self-Reporting Analysis

Of all the CVEs published by Canon Inc. as a CNA, 70.8% affect products that Canon Inc. develops as a vendor.

70.8%
29.2%
Self-reported: 34 (70.8%)
Third-party: 14 (29.2%)

Of all the CVEs published that affect products developed by Canon Inc., 41.0% are self-published by Canon Inc. as a CNA.

41.0%
59.0%
Self-published: 34 (41.0%)
Other CNAs: 49 (59.0%)

Products(608 total)

Top CVEs

Signals from CVEs in this vendor scope (83 CVEs).

83 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2006-1185HIGH
Unspecified vulnerability in Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via certain invalid HTML that causes memory corruption.
Apr 11, 20067.569NOYES
CVE-2006-1188HIGH
Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via HTML elements with a certain crafted tag, which leads to memory corruption.
Apr 11, 20067.563NOYES
CVE-2021-38154HIGH
Certain Canon devices manufactured in 2012 through 2020 (such as imageRUNNER ADVANCE iR-ADV C5250), when Catwalk Server is enabled for HTTP access, allow remote attackers to modify
Aug 29, 20217.537NOYES
CVE-2026-9261CRITICAL
Use of weak SSH cryptographic algorithms in Canon EOS Network Setting Tool Version 1.5.0 or earlier
Jun 16, 20269.836NONO
CVE-2026-9260CRITICAL
Use of hard-coded cryptographic keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier
Jun 16, 20269.834NONO
CVE-2025-14236CRITICAL
Buffer overflow in Address Book attribute tag processing on Small Office Multifunction Printers(*) which may allow an attacker on the network segment to trigger the affected produc
Jan 16, 20269.834NONO
CVE-2025-14234CRITICAL
Buffer overflow in CPCA list processing on Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected prod
Jan 16, 20269.834NONO
CVE-2025-14231CRITICAL
Buffer overflow in print job processing by WSD on Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affect
Jan 16, 20269.834NONO
CVE-2021-38085HIGH
The Canon TR150 print driver through 3.71.2.10 is vulnerable to a privilege escalation issue. During the add printer process, a local attacker can overwrite CNMurGE.dll and, if tim
Aug 11, 20217.834NOYES
CVE-2026-9259CRITICAL
Improper validation of server certificates in Canon EOS Network Setting Tool Version 1.5.0 or earlier
Jun 16, 20269.833NONO
View all 83 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products83 CVEs
29%
27%
42%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local2 (2.4%)
Network55 (66.3%)
Unknown15 (18.1%)
Physical1 (1.2%)
Adjacent Network10 (12.0%)
Attack Complexity
Low67 (80.7%)
High1 (1.2%)
Unknown15 (18.1%)
User Interaction
None59 (71.1%)
Unknown15 (18.1%)
Required9 (10.8%)
Privileges Required
Low3 (3.6%)
High1 (1.2%)
None64 (77.1%)
Unknown15 (18.1%)

Exploit Exposure

Signals from CVEs in this vendor scope (83 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
3 CVEs
3.6% of CVEs· 98th percentile
Nuclei
1 CVE
1.2% of CVEs· 95th percentile
ExploitDB
7 CVEs
8.4% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Canon Inc..

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Canon Inc. — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Canon Inc.'s Products

View all 5 CNAs →

Top CWEs