Thursday , September 3 2026
canon

Canon patches multiple flaws allowing hackers remote access

Canon has issued a security alert for its laser and small office printers, revealing seven critical vulnerabilities that could let remote attackers fully control the devices. These flaws, which all have a CVSS score of 9.8, impact many imageCLASS, i-SENSYS, and Satera models available in the US, Europe, and Japan.

The main issue is how these printers handle network traffic when unprotected by a firewall. According to the advisory, the risk is acute “if a product is connected directly to the Internet without using a router (wired or Wi-Fi)”.

Google Unveils Gemini 3.8 Flash Cyber to Identify and Auto-Patch Security Flaws

Google has launched Gemini 3.8, its newest model for reasoning and coding. It includes a special version named Gemini 3.8...
Read More
Google Unveils Gemini 3.8 Flash Cyber to Identify and Auto-Patch Security Flaws

SonicWall SMA1000 SSRF Hits 10, Exploiting CVE-2026-83548 

SonicWall unveiled advisory SNWLID-2026-0016 on September 1, 2026. It states that two SMA1000 flaws are being actively exploited. The main...
Read More
SonicWall SMA1000 SSRF Hits 10, Exploiting CVE-2026-83548 

Gartner
70% of SOCs Will Pilot AI Agents: Only 15% Will See Results

The market for AI SOC agents is early, crowded, and full of claims that haven't been tested in production. This Gartner...
Read More
Gartner  70% of SOCs Will Pilot AI Agents: Only 15% Will See Results

CVE-2026-62911
Nearly 22,000 Microsoft Exchange Servers are vulnerable to attack

Almost 22,000 Microsoft Exchange servers are online and still vulnerable to a flaw that lets attackers access all user mailboxes. Tracked...
Read More
CVE-2026-62911  Nearly 22,000 Microsoft Exchange Servers are vulnerable to attack

CISA alerts on multiple PaperCut NG/MF flaws being actively exploited

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has listed two flaws in PaperCut NG and PaperCut MF in its...
Read More
CISA alerts on multiple PaperCut NG/MF flaws being actively exploited

Fire Ant hackers convert Cisco routers into spy platforms

The researchers discovered Fire Ant's new tactic after finding an active GRE (Generic Routing Encapsulation) tunnel interface on a Cisco...
Read More
Fire Ant hackers convert Cisco routers into spy platforms

Five Critical WordPress Flaws Lead to Site Takeover or RCE

Many serious security flaws have been found in WordPress plugins and themes, such as WPMU DEV Dashboard, Avada, TranslatePress, Pods,...
Read More
Five Critical WordPress Flaws Lead to Site Takeover or RCE

700 AI agents united to hack Hugging Face after breaking isolation

700 AI agents supposedly escaped their isolation, created a secret communication channel, and worked together to attack Hugging Face's systems....
Read More
700 AI agents united to hack Hugging Face after breaking isolation

ServiceNow warns of three critical security vulnerabilities

ServiceNow issued security updates for three new serious AI Platform problems that can be used in code injection, SQL injection,...
Read More
ServiceNow warns of three critical security vulnerabilities

100+ Tech and Security Orgs Urge Global Cyber Defense Boost Against AI Threats

Over 100 tech, cybersecurity, and finance groups have signed an open letter with OpenAI. They want a global increase in...
Read More
100+ Tech and Security Orgs Urge Global Cyber Defense Boost Against AI Threats

An unauthenticated remote attacker could exploit a vulnerability to cause a buffer overflow or invalid free, which may allow them to execute arbitrary code or cause a Denial-of-Service (DoS) attack. Essentially, a hacker could take control of the printer to steal documents, gain access to the network, or crash it permanently.

The advisory details a barrage of buffer overflow and memory corruption issues, each assigned the near-maximum severity score of 9.8.

CVE-2025-14231: Buffer overflow in “print job processing by WSD”.
CVE-2025-14232: Buffer overflow in “XML processing of XPS file”.
CVE-2025-14233: Invalid free in “CPCA file deletion processing”.
CVE-2025-14234: Buffer overflow in “CPCA list processing”.
CVE-2025-14235: Buffer overflow in “XPS font fpgm data processing”.
CVE-2025-14236: Buffer overflow in “Address Book attribute tag processing”.
CVE-2025-14237: Buffer overflow in “XPS font parse processing”.

Vulnerabilities affect devices with firmware v06.02 and earlier, and the specific models vary by region.

US: Color imageCLASS LBP630C/MF650C, imageCLASS LBP230, X LBP1238 II, and others.
Europe: i-SENSYS LBP630C/MF650C, imageRUNNER 1643i II, and others.
Japan: Satera LBP670C and MF750C Series.

“We advise that our customers install the latest firmware available,” the company stated, noting that fixes will be uploaded to local sales representative websites .

Physical isolation is currently the best defense. Canon recommends customers to set a private IP address for their products and use a firewall or router to limit network access.

Check Also

Zoom Flaw

AI Finds Nation-State-Level Zoom Flaw in Under 24 Hours, Zero-Click Attack Exposed

A serious security flaw in Zoom might let a hacker take control of someone else’s …