Cameras Menu
Lenses Menu
Video Menu
Ink, Toner & Paper Menu
Office Menu
Deals Menu
Office Product Deals
Support Menu
Shipping and Handling
Free Standard Shipping and Handling on Select Products
Offer valid May 18, 2026 12:05 a.m. ET through June 30, 2026 11:50 p.m. ET. Offer valid only on select products available for sale through the Canon online store. See product page for details. Offer not valid on bulk orders. Orders will be shipped to a street address in the 50 United States or the District of Columbia only. Free standard shipping and handling offer is a $5.99 to $15.99 Canon online store value. Offer subject to the Canon Terms of Sale. Dealers, distributors and other resellers are not eligible for this offer. Offer void where prohibited, taxed, or restricted.
CPA2026-005: Vulnerability Remediation for EOS Network Setting Tool
June 15, 2026
Canon Inc.
Description:
Canon U.S.A., Inc. has recently identified multiple vulnerabilities in the EOS Network Setting Tool, which is included with the EOS Utility installer. If these vulnerabilities are exploited, authentication information used in the FTP/FTPS/SFTP communication test function could be obtained by a third party.
As of the date of this notice, there have been no reports of these vulnerabilities being exploited. However, to enhance the security of the product, we recommend that our customers install the latest EOS Network Setting Tool, which is included in EOS Utility.
Affected Software:
- EOS Network Setting Tool Version 15.0 or earlier (for Windows and macOS), which is included in EOS Utility Versions 3.12.0 through 3.20.20 (inclusive).
For details of the affected software titles and versions, please refer to your product’s Software & Drivers download page on Canon USA’s website.
Mitigation/Remediation:
EOS Utility, which includes the EOS Network Setting Tool addressing these issues, is available on Canon USA’s website. We recommend that our customers install the latest EOS Utility and confirm that the following software version is installed: EOS Network Setting Tool Version 1.5.1 or later (for Windows and macOS), which is included in EOS Utility Version 3.20.21 or later.
CVE / CVSS:
CVE-2026-9258: Improper validation of SSH host keys in the EOS Network Setting Tool. CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N Base Score: 7.1.
CVE-2026-9259: Improper validation of server certificates in the EOS Network Setting Tool. CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N Base Score: 7.1.
CVE-2026-9260: Use of hard-coded cryptographic keys in the EOS Network Setting Tool. CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N Base Score: 6.9.
CVE-2026-9261: Use of weak SSH cryptographic algorithms in the EOS Network Setting Tool. CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N Base Score: 7.6.
CVE-2026-9262: Use of a non-secure protocol as the default FTP configuration in the EOS Network Setting Tool. CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N Base Score: 7.1.
Canon would like to thank the following researchers for identifying this vulnerability:
- CVE-2026-9258, CVE-2026-9259, CVE-2026-9260, CVE-2026-926, and CVE-2026-9261: Ryan Hausknecht (@haus3c)
Thanks for signing up!
The application has encountered an unknown error. Please try again in a few minutes!
By clicking Sign Up, you are opting to receive promotional, educational, e-commerce and product registration emails from Canon USA. You can update your preferences or unsubscribe at anytime.
Footer
ABOUT CANON
MYCANON
ORDER HELP
PRODUCT RESOURCES
Canon U.S.A., Inc. All Rights Reserved. Reproduction in whole or part without permission is prohibited.
| [+] FeedbackTo get the best possible experience using our website we recommend that you upgrade to a newer version of the web browser.
Just click an icon below to view the down load page: