ZeroHour

Vulnerabilities

14 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-34926
Directory Traversal in Trend Micro Apex One (On-Premise) Server

CVE-2026-34926 is a directory traversal vulnerability (CWE-23) in the on-premise edition of the Trend Micro Apex One endpoint management server. A pre-authenticated local attacker — someone with access to the Apex One server who has already obtained administrative credentials through some other method — can use the traversal to modify a key table on the server, injecting malicious code that the server then deploys to its managed agents. This gives the attacker a delivery channel to run malicious code on the agents managed by the exploited server (CVSS scope changed), which is why the 6.7 CVSS score reflects a local, high-complexity, high-privilege attack path with high confidentiality impact. Only on-premise Apex One deployments are exploitable; the cloud/SaaS edition is not affected by this flaw. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2026-05-21 (EPSS 12.7%, 96th percentile), though no public proof-of-concept is known and ransomware use has not been confirmed.

Do: Apply Trend Micro's fix for the Apex One on-premise server per the vendor security advisory (exact fixed versions are not stated in the available data — check the bulletin), or, for US federal agencies, satisfy the BOD 22-01/KEV required action of applying vendor mitigations or discontinuing use if mitigations are unavailable. Because exploitation requires administrative credentials obtained by some other method, review privileged accounts on Apex One servers for compromise, check the server's key table for unauthorized modifications, and look for unexpected or anomalous code distributed to managed agents. Ransomware use is unconfirmed but plausible; restrict local and administrative access to the server and monitor agent activity until patched.

6.713% KEV
  • Trend Micro Apex One (on-premise server)
largetens of thousands of on-premise Apex One server deployments worldwide (managed agent population likely in the millions); not publicly quantified
CVE-2025-54948
Pre-auth OS command injection in Trend Micro Apex One on-prem Management Console

Trend Micro Apex One's on-premises Management Console contains an OS command injection flaw (CWE-78) that a remote attacker can reach prior to authentication. By sending crafted requests to the console, the attacker can inject arbitrary OS commands and upload malicious code to the server hosting the console. Successful exploitation yields remote code execution on the Apex One management server, which typically holds privileged network access and controls the managed endpoint fleet. Only organizations running the on-premise Apex One Management Console are affected; the source data does not enumerate specific vulnerable builds. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-08-18, confirming active exploitation in the wild, though no public proof-of-concept is known and ransomware involvement is not yet confirmed.

Do: Apply Trend Micro's patched builds or vendor-directed mitigations for the on-prem Apex One Management Console immediately, per the CISA KEV required action and BOD 22-01 guidance (federal agencies face a KEV deadline). Restrict the Management Console from direct internet exposure via firewall or VPN, and hunt the management server for signs of compromise such as unexpected uploaded files or processes, since active exploitation is confirmed. Ransomware association is unconfirmed but should be assumed possible until vendor guidance says otherwise.

9.822% KEV
  • Trend Micro Apex One (on-premises Management Console)
large≈ tens of thousands of on-prem Management Console deployments (estimate; no published install counts in source data)
CVE-2023-41179
Arbitrary command execution in Trend Micro Apex One and Worry-Free Business Security

CVE-2023-41179 is a code-injection flaw (CWE-94) in the third-party AV uninstaller module shipped with Trend Micro Apex One (on-premises and SaaS), Worry-Free Business Security, and Worry-Free Business Security Services. An attacker who has first obtained administrative console access on the target system can manipulate this module to execute arbitrary commands. Successful exploitation yields remote code execution on the affected installation with high impact on confidentiality, integrity, and availability (CVSS 3.1: 7.2). Any organization running these Trend Micro endpoint-security management products is affected, especially those whose consoles are reachable by multiple or untrusted administrators. The flaw is being actively exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2023-09-21 and Trend Micro released urgent fixes, though no public proof-of-concept is known and ransomware use has not been confirmed.

Do: Apply Trend Micro's security patch/hotfix per vendor instructions immediately, or discontinue use of the product if mitigations are unavailable, as required by the CISA KEV listing. Because exploitation requires administrative console access, restrict console reachability to trusted networks or VPN, audit administrative accounts for anomalous activity, and monitor for signs of exploitation given the active in-the-wild abuse.

7.25% KEV
  • Trend Micro Apex One (on-premises and SaaS)
  • Trend Micro Worry-Free Business Security
  • Trend Micro Worry-Free Business Security Services
largetens of thousands of installations (order of 10^4-10^5)
CVE-2022-40139
Improper Validation RCE via Rollback Mechanism in Trend Micro Apex One Clients

CVE-2022-40139 is an improper validation flaw in components of the rollback mechanism in Trend Micro Apex One and Apex One as a Service endpoint clients. It is triggered when an Apex One server administrator instructs managed clients to download and apply a rollback package that is not properly verified, allowing a malicious or spoofed package to reach endpoints. An attacker who exploits this gains remote code execution on the affected client machines. Exploitation requires the attacker to first obtain access to the Apex One server administration console, so it typically serves as a post-compromise escalation path that spreads control from the management server to all managed endpoints. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-09-15 and Trend Micro addressed an actively exploited Apex One zero-day, though no public proof-of-concept is known and use in ransomware campaigns is unknown.

Do: Apply Trend Micro's Apex One updates per the vendor advisory and CISA's required action (September 2022 fix or later), and for Apex One as a Service confirm the SaaS console has pushed the updated agents to all endpoints. Because exploitation requires administration console access, restrict and monitor that console (limit accounts, use strong authentication, review recent logins), rotate admin credentials if compromise is suspected, and hunt for clients that downloaded or executed rollback packages around the compromise window. Ransomware association is unknown, so treat any console compromise as potentially precursor activity.

7.23% KEV
  • Trend Micro Apex One (on-premises) clients
  • Trend Micro Apex One as a Service (SaaS) clients
largelikely hundreds of thousands of endpoint agents worldwide (order of magnitude); exact count unknown
CVE-2022-26871
Unauthenticated Arbitrary File Upload RCE in Trend Micro Apex Central

CVE-2022-26871 is a critical (CVSS 9.8) arbitrary file upload flaw (CWE-345, insufficient verification of data authenticity) in Trend Micro Apex Central, the central management console for Trend Micro's endpoint protection. An unauthenticated remote attacker can send an upload request to a network-accessible interface without any credentials or user interaction, uploading an arbitrary file that can lead to remote code execution on the server. Successful exploitation gives the attacker code execution with high impact to confidentiality, integrity and availability on the affected management server, potentially providing a foothold into the wider network it manages. Organizations running Trend Micro Apex Central on-premise are affected; CISA also lists Apex One in the product CPE data, while CISA's affected-product entry names Apex Central. The flaw was added to the CISA Known Exploited Vulnerabilities Catalog on 2022-03-31, indicating observed exploitation in the wild, with EPSS estimating a 19.6% probability of exploitation within 30 days; no public PoC is known.

Do: Apply the updated Apex Central release per Trend Micro's security advisory and the CISA KEV required action (apply updates per vendor instructions); confirm with the vendor which build addresses CVE-2022-26871 for your deployment. Until patched, restrict internet exposure of the Apex Central management console to trusted networks and review the server for unexpected uploaded files or web/server processes launching children, given confirmed in-the-wild exploitation. Organizations managing Apex One endpoints via Apex Central should ensure the management server is prioritized, since compromise could expose endpoint fleet management functions.

9.820% KEV
  • Trend Micro Apex Central
  • Trend Micro Apex One
moderate≈1,000–10,000 on-premise management servers worldwide (estimated)
CVE-2021-36741
+1 in the same advisory: …36742
Authenticated Arbitrary File Upload in Trend Micro Apex One and OfficeScan Consoles

CVE-2021-36741 is an improper input validation flaw (CWE-434) in the management consoles of Trend Micro Apex One, Apex One as a Service, OfficeScan XG, and Worry-Free Business Security 10.0 SP1 that permits the upload of arbitrary files on affected installations. It is triggered remotely over the network (CVSS AV:N) by an attacker who has first obtained logon access to the product's management console (PR:L), with no user interaction required. Successful exploitation lets the attacker place arbitrary files on the management server, with high potential impact to confidentiality, integrity, and availability (CVSS 3.1 score 8.8). Organizations running any of these Trend Micro endpoint-security consoles are affected, including tenants of the cloud-hosted Apex One as a Service. The flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03), indicating known in-the-wild exploitation; no public proof-of-concept is known, ransomware use is unconfirmed, and news reports indicate attackers attempted to exploit zero-days in the Trend Micro Apex One platform.

Do: Apply Trend Micro's patches to on-premises Apex One, OfficeScan XG, and Worry-Free Business Security 10.0 SP1 per the vendor advisories and CISA's required action, and confirm the Apex One as a Service-hosted console has been updated by Trend Micro. Because exploitation requires an authenticated console session, restrict management-console logon to trusted administrators, use strong credentials/MFA, and audit console logs for unexpected file uploads or unfamiliar sessions. Treat any internet-exposed management console as higher risk and prioritize patching it.

8.8
group max
5% KEV
  • Trend Micro Apex One (on-premises)
  • Trend Micro Apex One as a Service hosted SaaS service (no local version applies)
  • Trend Micro OfficeScan XG
  • +1 more
largelikely tens of thousands of management console deployments worldwide across the four products, plus all Apex One as a Service tenants (order-of-magnitude…
CVE-2020-24557
Improper Access Control LPE in Trend Micro Apex One and Worry-Free Business Security

Trend Micro Apex One, OfficeScan, and Worry-Free Business Security 10.0 SP1 on Microsoft Windows contain an improper access control flaw that lets an attacker manipulate a specific product folder to temporarily disable the security product and abuse a Windows function to escalate privileges. The attacker must first obtain the ability to execute low-privileged code on the target system; Windows 10 version 1909 (OS Build 18363.719) mitigates the hard-link technique, so earlier Windows versions are the easier targets. Successful exploitation yields local privilege escalation with high impact on confidentiality, integrity, and availability (CVSS 3.1: 7.8). Any organization running these Trend Micro endpoint agents on unpatched Windows machines is affected, with exposure driven by fleet size rather than internet-facing services. The vulnerability is being exploited in the wild per vendor advisories and news coverage, and CISA added it to the KEV catalog on 2021-11-03 with the required action of applying vendor updates; no public proof-of-concept is documented.

Do: Apply Trend Micro's patched builds for Apex One and Worry-Free Business Security 10.0 SP1 per the vendor advisory, as CISA's required action directs. Prioritize hosts running Windows versions older than Windows 10 1909 (OS Build 18363.719), where the hard-link mitigation is absent, and verify no unpatched agents remain in your fleet. Also check endpoints for signs of prior low-privileged code execution and local privilege escalation, since the flaw requires an existing foothold to exploit.

7.83% KEV
  • Trend Micro Apex One
  • Trend Micro OfficeScan
  • Trend Micro Worry-Free Business Security 10.0 SP1
largehundreds of thousands of managed Windows endpoints (order-of-magnitude estimate)
CVE-2020-8599
+1 in the same advisory: …8467
Unauthenticated File Write & Auth Bypass in Trend Micro Apex One/OfficeScan

Trend Micro Apex One (2019) and OfficeScan XG on-premises servers ship a vulnerable EXE file that an unauthenticated remote attacker can abuse to write arbitrary data to an arbitrary path on the server and to bypass ROOT login. Because the flaw is reachable over the network and requires no credentials or user interaction, any exposed management server is directly attackable. Successful exploitation effectively grants an attacker full control of the endpoint-management server, which typically holds central administration over an organization's entire endpoint-security estate. Organizations running on-premises Apex One (2019) or OfficeScan XG servers are affected, particularly those whose consoles are reachable from the internet. The vulnerability is confirmed in the wild — it was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03 — and its EPSS score of ~11.9% (96th percentile) indicates a meaningful probability of continued exploitation; no public PoC is known.

Do: Apply Trend Micro's updates for Apex One (2019) and OfficeScan XG per the vendor advisory, as this is CISA's required action for KEV-listed vulnerabilities. Identify any internet-exposed Apex One or OfficeScan consoles — especially on-premises management servers reachable on default web/console ports — and restrict or firewall access until patched. After patching, check the server for unexpected file modifications and review accounts/logs for signs of a ROOT login bypass.

9.8
group max
12% KEV
  • Trend Micro Apex One Apex One (2019) on-premises server
  • Trend Micro OfficeScan OfficeScan XG server
largeon the order of 10,000–100,000 deployed Apex One/OfficeScan management servers (tens of thousands of organizations; millions of endpoints behind them)
CVE-2020-8468
Authenticated content validation escape in Trend Micro Apex One, OfficeScan, WFWBS agents

CVE-2020-8468 is a content validation escape (CWE-74, an injection-class flaw) in the client agents of Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security 9.0/9.5/10.0. The attack is network-based but requires the attacker to already hold valid user credentials (CVSS PR:L); once authenticated, they can send crafted content that escapes validation and manipulates certain agent client components on the endpoint. Because the manipulable components are the endpoint security agent itself, impact is rated high for confidentiality, integrity and availability (CVSS 3.1 score 8.8), giving an authenticated attacker a way to tamper with or abuse the protection software on the host. Any organization running these on-premises Trend Micro endpoint agents is affected. The flaw is on CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03) with active exploitation reported in the wild (contemporaneous coverage described attackers attempting to exploit two Apex One zero-days), though a ransomware link is unknown, no public PoC is catalogued, and EPSS estimates a 5.8% probability of exploitation in the next 30 days (93rd percentile).

Do: Apply the Trend Micro-supplied fixes to all Apex One (2019), OfficeScan XG and Worry-Free Business Security 9.0/9.5/10.0 agents per the vendor advisory, as required by the CISA KEV listing. Because exploitation requires valid credentials, review authentication logs for compromised accounts and hunt for signs of unauthorized manipulation of agent components on any unpatched endpoints. Treat unpatched agents as exposed to active attacks; the possible use in ransomware campaigns is currently unknown.

8.86% KEV
  • Trend Micro Apex One 2019 (agent)
  • Trend Micro OfficeScan XG (agent)
  • Trend Micro Worry-Free Business Security 9.0, 9.5, 10.0 (agent)
masslikely on the order of millions of endpoints worldwide (est.)
CVE-2019-18187
Directory Traversal RCE in Trend Micro OfficeScan

Trend Micro OfficeScan contains a directory traversal flaw (CWE-22) in its handling of ZIP archives: when a zip file is extracted to a designated folder on the OfficeScan server, archive entries can escape that folder, allowing an attacker to place files at exploitable locations and achieve remote code execution. The flaw is triggered by getting the server to extract an attacker-influenced ZIP archive into the specific folder on the OfficeScan server. Successful exploitation yields arbitrary code execution on the OfficeScan management server, which typically holds broad control over the managed endpoint fleet and can serve as a foothold for lateral movement. Any organization running an on-premises Trend Micro OfficeScan deployment is affected; the source data does not specify affected version ranges. The vulnerability was added to the CISA KEV catalog on 2021-11-03 (indicating observed exploitation, with ransomware use unknown), and EPSS assigns a 25.1% probability of exploitation within 30 days (98th percentile); no public PoC is known.

Do: Apply Trend Micro's updates per vendor instructions, as required by CISA's KEV listing, and verify the patched build against Trend Micro's advisory since specific version numbers are not provided here (note that OfficeScan was succeeded by Trend Micro Apex One, so confirm patched status on migrated installs). Inventory for internet-exposed OfficeScan/Apex One management consoles and restrict access to trusted networks, and hunt for evidence of exploitation given the confirmed in-the-wild status.

7.525% KEV
  • Trend Micro OfficeScan
large≈10k–100k on-premises OfficeScan management server deployments (estimate; millions of managed endpoints)
CVE-2016-5840
hotfix_upload.cgi in Trend Micro Deep Discovery Inspector (DDI) 3.7, 3.8 SP1 (3.81), and 3.8 SP2 (3.82) allows remote administrators to execute arbitrary code v

hotfix_upload.cgi in Trend Micro Deep Discovery Inspector (DDI) 3.7, 3.8 SP1 (3.81), and 3.8 SP2 (3.82) allows remote administrators to execute arbitrary code via shell metacharacters in the filename parameter of the Content-Disposition header.

NVD description · AI analysis pending
7.28% PoC
  • trend micro deep discovery inspector
CVE-2016-3664
Trend Micro Mobile Security for iOS before 3.2.1188 does not verify the X.509 certificate of the mobile application login server, which allows man-in-the-middle

Trend Micro Mobile Security for iOS before 3.2.1188 does not verify the X.509 certificate of the mobile application login server, which allows man-in-the-middle attackers to spoof this server and obtain sensitive information via a crafted certificate.

NVD description · AI analysis pending
7.4<1%
  • trend micro mobile security