Skip to content
Signals
NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-20349 · Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability · Added 2026-08-11 · Due 2026-08-14CISA KEV · CVE-2026-68820 · Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability · Added 2026-08-11 · Due 2026-08-25NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-20349 · Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability · Added 2026-08-11 · Due 2026-08-14CISA KEV · CVE-2026-68820 · Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability · Added 2026-08-11 · Due 2026-08-25

Vendors · konicaminolta

konicaminolta

· 2 Critical

Total CVEs

15

Critical

2

Products

180

Search All CVEs →

15

Products (180)

bizhub 458 firmware8 CVEsbizhub 2278 CVEsbizhub 227 firmware8 CVEsbizhub 2878 CVEsbizhub 287 firmware8 CVEsbizhub 3088 CVEsbizhub 308 firmware8 CVEsbizhub 308e8 CVEsbizhub 308e firmware8 CVEsbizhub 3688 CVEsbizhub 368 firmware8 CVEsbizhub 368e8 CVEsbizhub 368e firmware8 CVEsbizhub 40528 CVEsbizhub 4052 firmware8 CVEsbizhub 4588 CVEsbizhub 458e8 CVEsbizhub 458e firmware8 CVEsbizhub 47528 CVEsbizhub 4752 firmware8 CVEsbizhub 5588 CVEsbizhub 558 firmware8 CVEsbizhub 558e8 CVEsbizhub 558e firmware8 CVEsbizhub 658e8 CVEsbizhub 658e firmware8 CVEsbizhub 7588 CVEsbizhub 758 firmware8 CVEsbizhub 8088 CVEsbizhub 808 firmware8 CVEsbizhub 9588 CVEsbizhub 958 firmware8 CVEsbizhub c2278 CVEsbizhub c227 firmware8 CVEsbizhub c2588 CVEsbizhub c258 firmware8 CVEsbizhub c2878 CVEsbizhub c287 firmware8 CVEsbizhub c3088 CVEsbizhub c308 firmware8 CVEsbizhub c33518 CVEsbizhub c3351 firmware8 CVEsbizhub c3688 CVEsbizhub c368 firmware8 CVEsbizhub c38518 CVEsbizhub c3851 firmware8 CVEsbizhub c3851fs8 CVEsbizhub c3851fs firmware8 CVEsbizhub c4588 CVEsbizhub c458 firmware8 CVEsbizhub c5588 CVEsbizhub c558 firmware8 CVEsbizhub c6588 CVEsbizhub c658 firmware8 CVEsbizhub c6598 CVEsbizhub c659 firmware8 CVEsbizhub c7598 CVEsbizhub c759 firmware8 CVEsbizhub c450i7 CVEsbizhub 306i7 CVEsbizhub 246i firmware7 CVEsbizhub 246i7 CVEsbizhub c250i7 CVEsbizhub c250i firmware7 CVEsbizhub c360i firmware7 CVEsbizhub c360i7 CVEsbizhub c4000i7 CVEsbizhub c550i7 CVEsbizhub c550i firmware7 CVEsbizhub 306i firmware7 CVEsbizhub c450i firmware7 CVEsbizhub c4050i firmware7 CVEsbizhub c4050i7 CVEsbizhub c650i7 CVEsbizhub 226i firmware7 CVEsbizhub 226i7 CVEsbizhub c300i7 CVEsbizhub c300i firmware7 CVEsbizhub c650i firmware7 CVEsbizhub c4000i firmware7 CVEsbizhub c3350i firmware7 CVEsbizhub c3350i7 CVEsbizhub c3320i firmware7 CVEsbizhub c3320i7 CVEsbizhub c3300i7 CVEsbizhub c3300i firmware7 CVEsbizhub c6545 CVEsbizhub 554e5 CVEsbizhub c4545 CVEsbizhub 6545 CVEsbizhub 654 firmware5 CVEsbizhub 654e5 CVEsbizhub 654e firmware5 CVEsbizhub c454 firmware5 CVEsbizhub c454e5 CVEsbizhub 7545 CVEsbizhub 754 firmware5 CVEsbizhub 754e5 CVEsbizhub 754e firmware5 CVEsbizhub c454e firmware5 CVEsbizhub c7545 CVEsbizhub c5545 CVEsbizhub c2245 CVEsbizhub c224 firmware5 CVEsbizhub c224e5 CVEsbizhub c224e firmware5 CVEsbizhub c554 firmware5 CVEsbizhub c554e5 CVEsbizhub c554e firmware5 CVEsbizhub c754 firmware5 CVEsbizhub c2845 CVEsbizhub c284 firmware5 CVEsbizhub c284e5 CVEsbizhub c284e firmware5 CVEsbizhub c754e5 CVEsbizhub c654 firmware5 CVEsbizhub c654e5 CVEsbizhub 224e5 CVEsbizhub 224e firmware5 CVEsbizhub 284e5 CVEsbizhub 284e firmware5 CVEsbizhub c3645 CVEsbizhub c364 firmware5 CVEsbizhub c364e5 CVEsbizhub c364e firmware5 CVEsbizhub c654e firmware5 CVEsbizhub c754e firmware5 CVEsbizhub 364e5 CVEsbizhub 364e firmware5 CVEsftp utility5 CVEsbizhub 454e5 CVEsbizhub 454e firmware5 CVEsbizhub 554e firmware5 CVEsbizhub 450i firmware4 CVEsbizhub c750i4 CVEsbizhub 750i4 CVEsbizhub 4700i4 CVEsbizhub 300i4 CVEsbizhub 300i firmware4 CVEsbizhub c750i firmware4 CVEsbizhub 750i firmware4 CVEsbizhub 4700i firmware4 CVEsbizhub 266i firmware4 CVEsbizhub 266i4 CVEsbizhub 4750i4 CVEsbizhub 360i4 CVEsbizhub 360i firmware4 CVEsbizhub 4750i firmware4 CVEsbizhub 650i firmware4 CVEsbizhub 650i4 CVEsbizhub 450i4 CVEsbizhub 550i firmware4 CVEsbizhub 550i4 CVEsbizhub c227i4 CVEsbizhub c227i firmware4 CVEsbizhub c257i4 CVEsbizhub c257i firmware4 CVEsbizhub c287i4 CVEsbizhub c287i firmware4 CVEsbizhub 4050i4 CVEsbizhub 4050i firmware4 CVEsbizhub 3673 CVEsbizhub 367 firmware3 CVEsbizhub pro958 firmware3 CVEsbizhub pro9583 CVEsbizhub2 CVEsbizhub c3100p firmware1 CVEsbizhub c3100p1 CVEsbizhub c3350 firmware1 CVEsbizhub c33501 CVEsbizhub c31101 CVEsbizhub c3110 firmware1 CVEsbizhub 4050 firmware1 CVEsbizhub 40501 CVEsbizhub c3850fs firmware1 CVEsbizhub c3850fs1 CVEsbizhub c3850 firmware1 CVEsbizhub c38501 CVEsbizhub 4750 firmware1 CVEsbizhub 47501 CVEs

Recent Vulnerabilities

View all 15
CVE-2020-37069CRITICAL 9.8

Konica Minolta FTP Utility 1.0 contains a buffer overflow vulnerability in the NLST command that allows attackers to overwrite system registers. Attackers can send an oversized buffer of 1500 'A' characters to crash the FTP server and potentially execute unauthorized code.

CVE-2020-37068CRITICAL 9.8

Konica Minolta FTP Utility 1.0 contains a buffer overflow vulnerability in the LIST command that allows attackers to overwrite system registers. Attackers can send an oversized buffer of 1500 'A' characters to crash the FTP server and potentially execute unauthorized code.

CVE-2025-5885MEDIUM 4.3

A vulnerability has been found in Konica Minolta bizhub up to 20250202 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-5884LOW 3.5

A vulnerability, which was classified as problematic, was found in Konica Minolta bizhub up to 20250202. This affects an unknown part of the component Display MFP Information List. The manipulation of the argument Model Name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2022-29588HIGH 7.5

Konica Minolta bizhub MFP devices before 2022-04-14 use cleartext password storage for the /var/log/nginx/html/ADMINPASS and /etc/shadow files.

CVE-2022-29587MEDIUM 4.0

Konica Minolta bizhub MFP devices before 2022-04-14 have an internal Chromium browser that executes with root (aka superuser) access privileges.

CVE-2022-29586HIGH 7.4

Konica Minolta bizhub MFP devices before 2022-04-14 allow a Sandbox Escape. An attacker must attach a keyboard to a USB port, press F12, and then escape from the kiosk mode.

CVE-2021-20872MEDIUM 6.8

Protection mechanism failure vulnerability in KONICA MINOLTA bizhub series (bizhub C750i G00-35 and earlier, bizhub C650i/C550i/C450i G00-B6 and earlier, bizhub C360i/C300i/C250i G00-B6 and earlier, bizhub 750i/650i/550i/450i G00-37 and earlier, bizhub 360i/300i G00-33 and earlier, bizhub C287i/C257i/C227i G00-19 and earlier, bizhub 306i/266i/246i/226i G00-B6 and earlier, bizhub C759/C659 GC7-X8 and earlier, bizhub C658/C558/C458 GC7-X8 and earlier, bizhub 958/808/758 GC7-X8 and earlier, bizhub 658e/558e/458e GC7-X8 and earlier, bizhub C287/C227 GC7-X8 and earlier, bizhub 287/227 GC7-X8 and earlier, bizhub 368e/308e GC7-X8 and earlier, bizhub C368/C308/C258 GC9-X4 and earlier, bizhub 558/458/368/308 GC9-X4 and earlier, bizhub C754e/C654e GDQ-M0 and earlier, bizhub 754e/654e GDQ-M0 and earlier, bizhub C554e/C454e GDQ-M1 and earlier, bizhub C364e/C284e/C224e GDQ-M1 and earlier, bizhub 554e/454e/364e/284e/224e GDQ-M1 and earlier, bizhub C754/C654 C554/C454 GR1-M0 and earlier, bizhub C364/C284/C224 GR1-M0 and earlier, bizhub 754/654 GR1-M0 and earlier, bizhub C3851FS/C3851/C3351 GC9-X4 and earlier, bizhub 4752/4052 GC9-X4 and earlier) allows a physical attacker to bypass the firmware integrity verification and to install malicious firmware.

CVE-2021-20871MEDIUM 6.5

Exposure of sensitive information to an unauthorized actor vulnerability in KONICA MINOLTA bizhub series (bizhub C750i G00-35 and earlier, bizhub C650i/C550i/C450i G00-B6 and earlier, bizhub C360i/C300i/C250i G00-B6 and earlier, bizhub 750i/650i/550i/450i G00-37 and earlier, bizhub 360i/300i G00-33 and earlier, bizhub C287i/C257i/C227i G00-19 and earlier, bizhub 306i/266i/246i/226i G00-B6 and earlier, bizhub C759/C659 GC7-X8 and earlier, bizhub C658/C558/C458 GC7-X8 and earlier, bizhub 958/808/758 GC7-X8 and earlier, bizhub 658e/558e/458e GC7-X8 and earlier, bizhub C287/C227 GC7-X8 and earlier, bizhub 287/227 GC7-X8 and earlier, bizhub 368e/308e GC7-X8 and earlier, bizhub C368/C308/C258 GC9-X4 and earlier, bizhub 558/458/368/308 GC9-X4 and earlier, bizhub C754e/C654e GDQ-M0 and earlier, bizhub 754e/654e GDQ-M0 and earlier, bizhub C554e/C454e GDQ-M1 and earlier, bizhub C364e/C284e/C224e GDQ-M1 and earlier, bizhub 554e/454e/364e/284e/224e GDQ-M1 and earlier, bizhub C754/C654 C554/C454 GR1-M0 and earlier, bizhub C364/C284/C224 GR1-M0 and earlier, bizhub 754/654 GR1-M0 and earlier, bizhub C4050i/C3350i/C4000i/C3300i G00-B6 and earlier, bizhub C3320i G00-B6 and earlier, bizhub 4750i/4050i G00-22 and earlier, bizhub 4700i G00-22 and earlier, bizhub C3851FS/C3851/C3351 GC9-X4 and earlier, and bizhub 4752/4052 GC9-X4 and earlier) allows an attacker on the adjacent network to obtain the credentials if the destination information including credentials are registered in the address book via a specific SOAP message.

CVE-2021-20870MEDIUM 4.6

Improper handling of exceptional conditions vulnerability in KONICA MINOLTA bizhub series (bizhub C750i G00-35 and earlier, bizhub C650i/C550i/C450i G00-B6 and earlier, bizhub C360i/C300i/C250i G00-B6 and earlier, bizhub 750i/650i/550i/450i G00-37 and earlier, bizhub 360i/300i G00-33 and earlier, bizhub C287i/C257i/C227i G00-19 and earlier, bizhub 306i/266i/246i/226i G00-B6 and earlier, bizhub C759/C659 GC7-X8 and earlier, bizhub C658/C558/C458 GC7-X8 and earlier, bizhub 958/808/758 GC7-X8 and earlier, bizhub 658e/558e/458e GC7-X8 and earlier, bizhub C287/C227 GC7-X8 and earlier, bizhub 287/227 GC7-X8 and earlier, bizhub 368e/308e GC7-X8 and earlier, bizhub C368/C308/C258 GC9-X4 and earlier, bizhub 558/458/368/308 GC9-X4 and earlier, bizhub C754e/C654e GDQ-M0 and earlier, bizhub 754e/654e GDQ-M0 and earlier, bizhub C554e/C454e GDQ-M1 and earlier, bizhub C364e/C284e/C224e GDQ-M1 and earlier, bizhub 554e/454e/364e/284e/224e GDQ-M1 and earlier, bizhub C754/C654 C554/C454 GR1-M0 and earlier, bizhub C364/C284/C224 GR1-M0 and earlier, bizhub 754/654 GR1-M0 and earlier, bizhub C4050i/C3350i/C4000i/C3300i G00-B6 and earlier, bizhub C3320i G00-B6 and earlier, bizhub 4750i/4050i G00-22 and earlier, bizhub 4700i G00-22 and earlier, bizhub C3851FS/C3851/C3351 GC9-X4 and earlier, bizhub 4752/4052 GC9-X4 and earlier, bizhub C3850/C3350/3850FS, bizhub 4750/4050, bizhub C3110, bizhub C3100P) allows a physical attacker to obtain unsent scanned image data when scanned data transmission is stopped due to the network error by ejecting a HDD before the scan job times out.

CVE-2021-20869MEDIUM 6.5

Exposure of sensitive information to an unauthorized actor vulnerability in KONICA MINOLTA bizhub series (bizhub C750i G00-35 and earlier, bizhub C650i/C550i/C450i G00-B6 and earlier, bizhub C360i/C300i/C250i G00-B6 and earlier, bizhub 750i/650i/550i/450i G00-37 and earlier, bizhub 360i/300i G00-33 and earlier, bizhub C287i/C257i/C227i G00-19 and earlier, bizhub 306i/266i/246i/226i G00-B6 and earlier, bizhub C759/C659 GC7-X8 and earlier, bizhub C658/C558/C458 GC7-X8 and earlier, bizhub 958/808/758 GC7-X8 and earlier, bizhub 658e/558e/458e GC7-X8 and earlier, bizhub C287/C227 GC7-X8 and earlier, bizhub 287/227 GC7-X8 and earlier, bizhub 368e/308e GC7-X8 and earlier, bizhub C368/C308/C258 GC9-X4 and earlier, bizhub 558/458/368/308 GC9-X4 and earlier, bizhub C754e/C654e GDQ-M0 and earlier, bizhub 754e/654e GDQ-M0 and earlier, bizhub C554e/C454e GDQ-M1 and earlier, bizhub C364e/C284e/C224e GDQ-M1 and earlier, bizhub 554e/454e/364e/284e/224e GDQ-M1 and earlier, bizhub C754/C654 C554/C454 GR1-M0 and earlier, bizhub C364/C284/C224 GR1-M0 and earlier, bizhub 754/654 GR1-M0 and earlier, bizhub C4050i/C3350i/C4000i/C3300i G00-B6 and earlier, bizhub C3320i G00-B6 and earlier, bizhub 4750i/4050i G00-22 and earlier, bizhub 4700i G00-22 and earlier, bizhub C3851FS/C3851/C3351 GC9-X4 and earlier, and bizhub 4752/4052 GC9-X4 and earlier) allows an attacker on the adjacent network to obtain some of user credentials if LDAP server authentication is enabled via a specific SOAP message.

CVE-2021-20868MEDIUM 4.5

Incorrect authorization vulnerability in KONICA MINOLTA bizhub series (bizhub C750i G00-35 and earlier, bizhub C650i/C550i/C450i G00-B6 and earlier, bizhub C360i/C300i/C250i G00-B6 and earlier, bizhub 750i/650i/550i/450i G00-37 and earlier, bizhub 360i/300i G00-33 and earlier, bizhub C287i/C257i/C227i G00-19 and earlier, bizhub 306i/266i/246i/226i G00-B6 and earlier, bizhub C759/C659 GC7-X8 and earlier, bizhub C658/C558/C458 GC7-X8 and earlier, bizhub 958/808/758 GC7-X8 and earlier, bizhub 658e/558e/458e GC7-X8 and earlier, bizhub C287/C227 GC7-X8 and earlier, bizhub 287/227 GC7-X8 and earlier, bizhub 368e/308e GC7-X8 and earlier, bizhub C368/C308/C258 GC9-X4 and earlier, bizhub 558/458/368/308 GC9-X4 and earlier, bizhub C754e/C654e GDQ-M0 and earlier, bizhub 754e/654e GDQ-M0 and earlier, bizhub C554e/C454e GDQ-M1 and earlier, bizhub C364e/C284e/C224e GDQ-M1 and earlier, bizhub 554e/454e/364e/284e/224e GDQ-M1 and earlier, bizhub C754/C654 C554/C454 GR1-M0 and earlier, bizhub C364/C284/C224 GR1-M0 and earlier, bizhub 754/654 GR1-M0 and earlier, bizhub C4050i/C3350i/C4000i/C3300i G00-B6 and earlier, bizhub C3320i G00-B6 and earlier, bizhub 4750i/4050i G00-22 and earlier, bizhub 4700i G00-22 and earlier, bizhub C3851FS/C3851/C3351 GC9-X4 and earlier, and bizhub 4752/4052 GC9-X4 and earlier) allows an attacker on the adjacent network to obtain user credentials if external server authentication is enabled via a specific SOAP message sent by an administrative user.

CVE-2015-7768

Buffer overflow in Konica Minolta FTP Utility 1.0 allows remote attackers to execute arbitrary code via a long CWD command.

CVE-2015-7767

Buffer overflow in Konica Minolta FTP Utility 1.0 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a long USER command.

CVE-2015-7603

Directory traversal vulnerability in Konica Minolta FTP Utility 1.0 allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in a RETR command.