target entity

Trend Micro

12 source-linked records in the current knowledge graph.

high

CVE-2026-34926: Trend Micro Apex One (On-Premise) Directory Traversal Vulnerability

Trend Micro Apex One (on-premise) contains a directory traversal vulnerability that could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-34926EPSS 12.7%Apex OneTrend Micro
CISA KEV ↗ · unattributed attribution
high

CVE-2025-54948: Trend Micro Apex One OS Command Injection Vulnerability

Trend Micro Apex One Management Console (on-premise) contains an OS command injection vulnerability that could allow a pre-authenticated remote attacker to upload malicious code and execute commands on affected installations. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-54948EPSS 20.8%Apex OneTrend Micro
CISA KEV ↗ · unattributed attribution
high

CVE-2023-41179: Trend Micro Apex One and Worry-Free Business Security Remote Code Execution Vulnerability

Trend Micro Apex One and Worry-Free Business Security contain an unspecified vulnerability in the third-party anti-virus uninstaller that could allow an attacker to manipulate the module to conduct remote code execution. An attacker must first obtain administrative console access on the target system in order to exploit this vulnerability. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-41179EPSS 4.7%Apex One and Worry-Free Business SecurityTrend Micro
CISA KEV ↗ · unattributed attribution
high

CVE-2019-18187: Trend Micro OfficeScan Directory Traversal Vulnerability

Trend Micro OfficeScan contains a directory traversal vulnerability by extracting files from a zip file to a specific folder on the OfficeScan server, leading to remote code execution. Required action: Apply updates per vendor instructions.

CVE-2019-18187EPSS 25.1%OfficeScanTrend Micro
CISA KEV ↗ · unattributed attribution
high

CVE-2020-8468: Trend Micro Multiple Products Content Validation Escape Vulnerability

Trend Micro Apex One, OfficeScan, and Worry-Free Business Security agents contain a content validation escape vulnerability that could allow an attacker to manipulate certain agent client components. Required action: Apply updates per vendor instructions.

CVE-2020-8468EPSS 5.8%Apex One, OfficeScan and Worry-Free Business Security AgentsTrend Micro
CISA KEV ↗ · unattributed attribution
high

CVE-2020-24557: Trend Micro Multiple Products Improper Access Control Vulnerability

Trend Micro Apex One, OfficeScan, and Worry-Free Business Security on Microsoft Windows contain an improper access control vulnerability that may allow an attacker to manipulate a particular product folder to disable the security temporarily, abuse a specific Windows function, and attain privilege escalation. Required action: Apply updates per vendor instructions.

CVE-2020-24557EPSS 2.6%Apex One, OfficeScan, and Worry-Free Business SecurityTrend Micro
CISA KEV ↗ · unattributed attribution