CPA2026-006: Multiple Vulnerabilities in Data Collection Agent

July 23, 2026

Multiple vulnerabilities have been identified in a component used by the Data Collection Agent*. If exploited, these vulnerabilities could potentially result in impacts such as denial of service (DoS) attacks or exposure of credentials used for proxy connections.

* This component is used only when [Monitoring Mode] is set to "CCA mode"; therefore, the Data Collection Agent is not affected by these vulnerabilities when [Monitoring Mode] is set to "Standard mode".

There have been no reports of these vulnerabilities being exploited. However, to enhance the security of the product, we advise that our customers install the latest Data Collection Agent.

We will continue to further strengthen our security measures to ensure that you can continue using Canon products with peace of mind. If these vulnerabilities are identified in other products, we will update this article.

Please note the affected software is Data Collection Agent Versions 2.0.2 to 2.0.4 (inclusive) and is only impacted when [Monitoring Mode] is set to "CCA mode".

An updated version of the Data Collection Agent (Version 2.0.5 or later) has been made available to address these vulnerabilities. Installation requires support from Service & Support personnel. Please contact your local Canon sales company for further information and guidance.

CVE

The following CVEs are addressed in this advisory:

  • CVE-2025-62168
  • CVE-2024-45802
  • CVE-2024-37894
  • CVE-2024-25617
  • CVE-2024-25111
  • CVE-2023-49286
  • CVE-2023-49285
  • CVE-2022-41317
  • CVE-2021-46784
  • CVE-2021-33620
  • CVE-2021-31808
  • CVE-2021-31807
  • CVE-2021-31806
GET SUPPORT
Need help with your product? Let us help you find what you need.
Product Support
NEED IT FIRST
Sign up for up-to-the-minute Canon News, Sales and Deals.
LEARN WITH CANON
Discover great new ways to enjoy your products with exclusive articles, training and events.
Learn more