Skip to main content

CVE-2026-9262

6.5
MEDIUMCVSS v3.1 Base Score
0.26%
LOW RiskEPSS (18th percentile)

Use of a non-secure protocol as the default FTP configuration in Canon EOS Network Setting Tool Version 1.5.0 or earlier

Published: 6/16/2026
Modified: 6/18/2026
Back to CVE Lookup

Vulnerability Summary

CVSS v3 Score

6.5MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

EPSS Score (Exploitation Probability)

0.26%LOW Exploitation Risk
18th percentile

This vulnerability has a 0.26% probability of being exploited in the next 30 days, ranking higher than 18% of all scored CVEs.

CWE Classification

Related Vulnerabilities

Same Weakness Type(CWE-1188)

CVE-2026-40994HIGH 8.2

Wss4jSecurityInterceptor initialized its BSP (WS-I Basic Security Profile) compliance flag so that inbound validation disabled WSS4J BSP enforcement on RequestData. Services that validate WS-Security on the network could therefore accept messages that violate BSP rules, weakening protocol-level checks. Affected versions: Spring Web Services 5.0.0 through 5.0.1; 4.1.0 through 4.1.3; 4.0.0 through 4.0.18; 3.1.0 through 3.1.8.

6/11/2026
CVE-2026-44109CRITICAL 9.8

OpenClaw before 2026.4.15 contains an authentication bypass vulnerability in Feishu webhook and card-action validation that allows unauthenticated requests to reach command dispatch. Missing encryptKey configuration and blank callback tokens fail open instead of rejecting requests, enabling attackers to bypass signature verification and replay protection to execute arbitrary commands.

5/6/2026
CVE-2025-5591MEDIUM 5.4

Kentico Xperience 13 is vulnerable to a stored cross-site scripting attack via a form component, allowing an attacker to hijack a victim user’s session and perform actions in their security context.

1/5/2026
CVE-2025-13357HIGH 7.4

Vault’s Terraform Provider incorrectly set the default deny_null_bind parameter for the LDAP auth method to false by default, potentially resulting in an insecure configuration. If the underlying LDAP server allowed anonymous or unauthenticated binds, this could result in authentication bypass. This vulnerability, CVE-2025-13357, is fixed in Vault Terraform Provider v5.5.0.

11/21/2025
CVE-2025-61481CRITICAL 10

An issue in MikroTik RouterOS v.7.14.2 and SwOS v.2.18 exposes the WebFig management interface over cleartext HTTP by default, allowing an on-path attacker to execute injected JavaScript in the administrator’s browser and intercept credentials.

10/27/2025

Similar SeverityMEDIUM