Trend Micro vendor intelligence

Trend Micro Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting Trend Micro products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.

Total KEVs
12
Known exploited vulnerabilities affecting Trend Micro products
In CISA KEV
12
Records also listed in the official catalog
Beyond CISA KEV
0
Additional exploited CVEs absent from CISA KEV
Sensor Observed
0
Trend Micro KEVs with sensor-observed exploitation activity

The catalog gap matters for Trend Micro exposure

All twelve exploited Trend Micro CVEs tracked here are also listed in CISA KEV. Use product ownership and sensor evidence to prioritize within this portfolio.

100%
Covered by CISA
0%
Beyond CISA
9
Product families

Attested Trend Micro CVEs

Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.

How exploitation is verified
CVE / description Product Confidence CISA KEV Added
CVE-2026-34926

A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the...

TrendAI Apex One, TrendAI Apex One as a Service Confirmed In CISA 01 Jun 2026
CVE-2025-54948

A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious code...

Trend Micro Apex One Confirmed In CISA 01 Jun 2026
CVE-2021-36741

An improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG, and Worry-Free Business Security 10.0 SP1...

Trend Micro Apex One, Trend Micro OfficeScan, Trend Micro Worry-Free Business Security Confirmed In CISA 03 Nov 2021
CVE-2021-36742

A improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG and Worry-Free Business Security 10.0 SP1...

Trend Micro Apex One, Trend Micro OfficeScan, Trend Micro Worry-Free Business Security Confirmed In CISA 03 Nov 2021
CVE-2020-8599

Trend Micro Apex One (2019) and OfficeScan XG server contain a vulnerable EXE file that could allow a remote attacker to write arbitrary data to an...

Trend Micro OfficeScan, Trend Micro Apex One Confirmed In CISA 03 Nov 2021
CVE-2020-24557

A vulnerability in Trend Micro Apex One and Worry-Free Business Security 10.0 SP1 on Microsoft Windows may allow an attacker to manipulate a...

Trend Micro Apex One, Trend Micro Worry-Free Business Security Confirmed In CISA 03 Nov 2021
CVE-2020-8468

Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) agents are affected by a content validation escape...

Trend Micro OfficeScan, Trend Micro Apex One, Trend Micro Worry-Free Business Security (WFBS) Confirmed In CISA 03 Nov 2021
CVE-2020-8467

A migration tool component of Trend Micro Apex One (2019) and OfficeScan XG contains a vulnerability which could allow remote attackers to execute...

Trend Micro OfficeScan, Trend Micro Apex One Confirmed In CISA 03 Nov 2021
CVE-2019-18187

Trend Micro OfficeScan versions 11.0 and XG (12.0) could be exploited by an attacker utilizing a directory traversal vulnerability to extract files...

Trend Micro OfficeScan Confirmed In CISA 03 Nov 2021
CVE-2022-26871

An arbitrary file upload vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to upload an arbitrary file which...

Trend Micro Apex Central Confirmed In CISA 31 Mar 2022
CVE-2022-40139

Improper validation of some components used by the rollback mechanism in Trend Micro Apex One and Trend Micro Apex One as a Service clients could...

Trend Micro Apex One Confirmed In CISA 15 Sep 2022
CVE-2023-41179

A vulnerability in the 3rd party AV uninstaller module contained in Trend Micro Apex One (on-prem and SaaS), Worry-Free Business Security and...

Trend Micro Apex One, Trend Micro Worry-Free Business Security, Trend Micro Worry-Free Business Security Services Confirmed In CISA 21 Sep 2023

Showing 12 of 12 Trend Micro known exploited vulnerabilities.

Recurring weakness patterns

Input validation, limitation, and relative path traversal account for three mapped occurrences across this Trend Micro KEV portfolio.

Browse all KEVs →

Early warning alerts

Get alerts on high-impact exploitation

Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.

Occasional high-impact alerts. Unsubscribe anytime. See our Privacy Policy.