Use of a broken or risky cryptographic algorithm in Canon Inc. products - CVE-2026-9261
Published: June 16, 2026
Vulnerability identifier: #VU134587
CSH Severity: High
CVSS v4.0: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2026-9261
CWE-ID: CWE-327
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vendor: Canon Inc.
Affected software:
EOS Network Setting Tool for macOS
EOS Network Setting Tool for Windows
EOS Utility
EOS Network Setting Tool for macOS
EOS Network Setting Tool for Windows
EOS Utility
Detailed vulnerability description
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to use of a vulnerable SSH encryption algorithm. A remote attacker can obtain credentials used for FTP/FTPS/SFTP communication test functions.
How to mitigate CVE-2026-9261
Install updates from vendor's website.