TL;DR

A critical vulnerability in the Canon imageCLASS MF654Cdw printer's XPS parser allows arbitrary code execution by network-adjacent attackers.

What happened

Vulnerability found in XPS parser Exploits enable remote code execution

Why it matters for ops

Lack of authentication for exploit Severe impact on security posture

Mitigation

  • Apply firmware updates immediately
  • Limit network access to affected devices

Action items

  • Verify device versions and apply patches
  • Monitor for exploitation attempts

Detection IOCs

  • Unusual network traffic from printers
  • Unexpected commands in print queue

Source link

http://www.zerodayinitiative.com/advisories/ZDI-26-204/