Trend Micro Vulnerabilities
Trend Micro is a cybersecurity vendor whose KEV entries center on Apex One endpoint security, the successor to OfficeScan, and related agent products. The database tracks 12 Trend Micro CVE records. CISA lists 12 of them as exploited in the wild, most recently on 2026-05-21. The most affected products are Apex One, Apex One and OfficeScan, Apex One, Apex One as a Service, and Worry-Free Business Security.
Recently Exploited Trend Micro CVEs
Trend Micro Apex One (On-Premise) Directory Traversal Vulnerability
Trend Micro Apex One OS Command Injection Vulnerability
Trend Micro Apex One and Worry-Free Business Security Remote Code Execution Vulnerability
Trend Micro Apex One and Apex One as a Service Improper Validation Vulnerability
Trend Micro Apex Central Arbitrary File Upload Vulnerability
Trend Micro OfficeScan Directory Traversal Vulnerability
Affected Products
9 products| Product | CVEs | KEV | Latest |
|---|---|---|---|
| Apex One | 2 | 2 | 2026-05-21 |
| Apex One and OfficeScan | 2 | 2 | 2021-11-03 |
| Apex One, Apex One as a Service, and Worry-Free Business Security | 2 | 2 | 2021-11-03 |
| Apex Central | 1 | 1 | 2022-03-31 |
| Apex One and Apex One as a Service | 1 | 1 | 2022-09-15 |
| Apex One and Worry-Free Business Security | 1 | 1 | 2023-09-21 |
| Apex One, OfficeScan and Worry-Free Business Security Agents | 1 | 1 | 2021-11-03 |
| Apex One, OfficeScan, and Worry-Free Business Security | 1 | 1 | 2021-11-03 |
| OfficeScan | 1 | 1 | 2021-11-03 |
Security Advisories
Weakness Types
All Trend Micro CVEs
12 records| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2026-34926 | Trend Micro Apex One (On-Premise) Directory Traversal Vulnerability | Trend Micro, Inc. | 6.7 | 0.5% | KEV | 2026-05-21 |
| CVE-2025-54948 | Trend Micro Apex One OS Command Injection Vulnerability | Trend Micro, Inc. | 9.4 | 23.9% | KEV | 2025-08-05 |
| CVE-2023-41179 | Trend Micro Apex One and Worry-Free Business Security Remote Code Execution Vulnerability | Trend Micro, Inc. | 7.2 | 4.3% | KEV | 2023-09-19 |
| CVE-2022-40139 | Trend Micro Apex One and Apex One as a Service Improper Validation Vulnerability | Trend Micro | 7.2 | 3.3% | KEV | 2022-09-19 |
| CVE-2022-26871 | Trend Micro Apex Central Arbitrary File Upload Vulnerability | Trend Micro | 9.8 | 19.5% | KEV | 2022-03-29 |
| CVE-2019-18187 | Trend Micro OfficeScan Directory Traversal Vulnerability | Trend Micro | 8.8 | 25.1% | KEV | 2019-10-28 |
| CVE-2020-8599 | Trend Micro Apex One and OfficeScan Authentication Bypass Vulnerability | Trend Micro | 9.8 | 11.9% | KEV | 2020-03-18 |
| CVE-2020-8467 | Trend Micro Apex One and OfficeScan Remote Code Execution Vulnerability | Trend Micro | 8.8 | 10.9% | KEV | 2020-03-18 |
| CVE-2020-8468 | Trend Micro Multiple Products Content Validation Escape Vulnerability | Trend Micro | 8.8 | 6.2% | KEV | 2020-03-18 |
| CVE-2021-36741 | Trend Micro Multiple Products Improper Input Validation Vulnerability | Trend Micro | 8.8 | 5.0% | KEV | 2021-07-29 |
| CVE-2020-24557 | Trend Micro Multiple Products Improper Access Control Vulnerability | Trend Micro | 7.8 | 2.7% | KEV | 2020-09-01 |
| CVE-2021-36742 | Trend Micro Multiple Products Improper Input Validation Vulnerability | Trend Micro | 7.8 | 1.5% | KEV | 2021-07-29 |
Frequently Asked Questions
How many Trend Micro vulnerabilities are actively exploited?→
12 Trend Micro CVEs are in the CISA Known Exploited Vulnerabilities catalog as of 2026-10-09. The latest was added on 2026-05-21.
Which Trend Micro products have the most exploited vulnerabilities?→
- +Apex One: 2 CVEs (2 in KEV)
- +Apex One and OfficeScan: 2 CVEs (2 in KEV)
- +Apex One, Apex One as a Service, and Worry-Free Business Security: 2 CVEs (2 in KEV)
- +Apex Central: 1 CVE (1 in KEV)
- +Apex One and Apex One as a Service: 1 CVE (1 in KEV)
Where does Trend Micro publish security advisories?→
Trend Micro publishes security advisories at https://success.trendmicro.com/en-US/vulnerability-response. Check the vendor advisory for fixed versions and workarounds before applying updates.
Sources
CVE record data © The MITRE Corporation, used under the CVE Terms of Use. Vendor and product names for exploited CVEs follow the CISA Known Exploited Vulnerabilities catalog (CC0). Exploit prediction scores by FIRST EPSS (first.org/epss). This site is not affiliated with or endorsed by Trend Micro, MITRE, CISA, or FIRST.