CPA2026-007: Vulnerability in PRISMAproduction

July 30, 2026

A deserialization vulnerability has been identified in PRISMAproduction. This vulnerability could potentially allow an unauthenticated attacker on an adjacent network to execute arbitrary code.

There have been no reports of these vulnerabilities being exploited. However, to enhance the security of the product, we advise that our customers install the latest PRISMAproduction version.

We will continue to further strengthen our security measures to ensure that you can continue using Canon products with peace of mind. If these vulnerabilities are identified in other products, we will update this article.

Please note the affected product is PRISMAproduction Version 6.5 or earlier.

A fix patch (Version 6.5.1 or later) is available. Installation of the patch requires assistance from Service & Support personnel. Please contact your local or regional Canon Service & Support representative to arrange installation.

CVE/CVSS

CVE-2026-3245: A deserialization vulnerability in PRISMAproduction that may lead to arbitrary code execution.

CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Base Score: 7.7.

Canon would like to thank the following researchers for identifying this vulnerability:

  • CVE-2026-3245: Anton Fabricius and Moritz Bechler working with SySS GmbH
GET SUPPORT
Need help with your product? Let us help you find what you need.
Product Support
NEED IT FIRST
Sign up for up-to-the-minute Canon News, Sales and Deals.
LEARN WITH CANON
Discover great new ways to enjoy your products with exclusive articles, training and events.
Learn more