ZeroHour

Vulnerabilities

550 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-71210
A vulnerability in the Trend Micro Apex One management console could allow a remote attacker to upload malicious code and execute commands on affected installat

A vulnerability in the Trend Micro Apex One management console could allow a remote attacker to upload malicious code and execute commands on affected installations. Please note: although this vulnerability carries a technical critical CVSS rating, this was reported via responsible disclosure via a researcher through the Zero Day Initiative. The SaaS versions of the product have already been mitigated and no customer action required. For this particular vulnerability, an attacker must have access to the Trend Micro Apex One Management Console, so customers that have their console�s IP address exposed externally should consider mitigating factors such as source restrictions if not already applied.

NVD description · AI analysis pending
9.8
group max
4%
  • trendmicro apex one
CVE-2026-34926
Directory Traversal in Trend Micro Apex One (On-Premise) Server

CVE-2026-34926 is a directory traversal vulnerability (CWE-23) in the on-premise edition of the Trend Micro Apex One endpoint management server. A pre-authenticated local attacker — someone with access to the Apex One server who has already obtained administrative credentials through some other method — can use the traversal to modify a key table on the server, injecting malicious code that the server then deploys to its managed agents. This gives the attacker a delivery channel to run malicious code on the agents managed by the exploited server (CVSS scope changed), which is why the 6.7 CVSS score reflects a local, high-complexity, high-privilege attack path with high confidentiality impact. Only on-premise Apex One deployments are exploitable; the cloud/SaaS edition is not affected by this flaw. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2026-05-21 (EPSS 12.7%, 96th percentile), though no public proof-of-concept is known and ransomware use has not been confirmed.

Do: Apply Trend Micro's fix for the Apex One on-premise server per the vendor security advisory (exact fixed versions are not stated in the available data — check the bulletin), or, for US federal agencies, satisfy the BOD 22-01/KEV required action of applying vendor mitigations or discontinuing use if mitigations are unavailable. Because exploitation requires administrative credentials obtained by some other method, review privileged accounts on Apex One servers for compromise, check the server's key table for unauthorized modifications, and look for unexpected or anomalous code distributed to managed agents. Ransomware use is unconfirmed but plausible; restrict local and administrative access to the server and monitor agent activity until patched.

6.713% KEV
  • Trend Micro Apex One (on-premise server)
largetens of thousands of on-premise Apex One server deployments worldwide (managed agent population likely in the millions); not publicly quantified
CVE-2025-69258
+2 in the same advisory: …69259 …69260
A LoadLibraryEX vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to load an attacker-controlled DLL into a key executabl

A LoadLibraryEX vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to load an attacker-controlled DLL into a key executable, leading to execution of attacker-supplied code under the context of SYSTEM on affected installations.

NVD description · AI analysis pending
9.8
group max
4% PoC
  • trendmicro apex central
CVE-2025-54987
A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious code and execute com

A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious code and execute commands on affected installations. This vulnerability is essentially the same as CVE-2025-54948 but targets a different CPU architecture.

NVD description · AI analysis pending
9.817%
  • trendmicro apex one
CVE-2025-54948
Pre-auth OS command injection in Trend Micro Apex One on-prem Management Console

Trend Micro Apex One's on-premises Management Console contains an OS command injection flaw (CWE-78) that a remote attacker can reach prior to authentication. By sending crafted requests to the console, the attacker can inject arbitrary OS commands and upload malicious code to the server hosting the console. Successful exploitation yields remote code execution on the Apex One management server, which typically holds privileged network access and controls the managed endpoint fleet. Only organizations running the on-premise Apex One Management Console are affected; the source data does not enumerate specific vulnerable builds. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-08-18, confirming active exploitation in the wild, though no public proof-of-concept is known and ransomware involvement is not yet confirmed.

Do: Apply Trend Micro's patched builds or vendor-directed mitigations for the on-prem Apex One Management Console immediately, per the CISA KEV required action and BOD 22-01 guidance (federal agencies face a KEV deadline). Restrict the Management Console from direct internet exposure via firewall or VPN, and hunt the management server for signs of compromise such as unexpected uploaded files or processes, since active exploitation is confirmed. Ransomware association is unconfirmed but should be assumed possible until vendor guidance says otherwise.

9.822% KEV
  • Trend Micro Apex One (on-premises Management Console)
large≈ tens of thousands of on-prem Management Console deployments (estimate; no published install counts in source data)
CVE-2025-53503
Trend Micro Cleaner One Pro is vulnerable to a Privilege Escalation vulnerability that could allow a local attacker to unintentionally delete privileged Trend M

Trend Micro Cleaner One Pro is vulnerable to a Privilege Escalation vulnerability that could allow a local attacker to unintentionally delete privileged Trend Micro files including its own.

NVD description · AI analysis pending
7.8<1%
  • trendmicro cleaner one
CVE-2025-53378
A missing authentication vulnerability in Trend Micro Worry-Free Business Security Services (WFBSS) agent could have allowed an unauthenticated attacker to remo

A missing authentication vulnerability in Trend Micro Worry-Free Business Security Services (WFBSS) agent could have allowed an unauthenticated attacker to remotely take control of the agent on affected installations. Also note: this vulnerability only affected the SaaS client version of WFBSS only, meaning the on-premise version of Worry-Free Business Security was not affected, and this issue was addressed in a WFBSS monthly maintenance update. Therefore no other customer action is required to mitigate if the WFBSS agents are on the regular SaaS maintenance deployment schedule and this disclosure is for informational purposes only.

NVD description · AI analysis pending
9.8<1%
  • trendmicro worry-free business security services
CVE-2025-52837
Trend Micro Password Manager (Consumer) version 5.8.0.1327 and below is vulnerable to a Link Following Privilege Escalation Vulnerability that could allow an at

Trend Micro Password Manager (Consumer) version 5.8.0.1327 and below is vulnerable to a Link Following Privilege Escalation Vulnerability that could allow an attacker the opportunity to abuse symbolic links and other methods to delete any file/folder and achieve privilege escalation.

NVD description · AI analysis pending
7.8<1%
  • trendmicro password manager
CVE-2025-52521
Trend Micro Security 17.8 (Consumer) is vulnerable to a link following local privilege escalation vulnerability that could allow a local attacker to unintention

Trend Micro Security 17.8 (Consumer) is vulnerable to a link following local privilege escalation vulnerability that could allow a local attacker to unintentionally delete privileged Trend Micro files including its own.

NVD description · AI analysis pending
7.1<1%
  • trendmicro maximum security 2022
CVE-2025-49385
+1 in the same advisory: …49384
Trend Micro Security 17.8 (Consumer) is vulnerable to a link following local privilege escalation vulnerability that could allow a local attacker to unintention

Trend Micro Security 17.8 (Consumer) is vulnerable to a link following local privilege escalation vulnerability that could allow a local attacker to unintentionally delete privileged Trend Micro files including its own.

NVD description · AI analysis pending
7.1<1%
  • trendmicro maximum security 2022
CVE-2025-49213
An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code execution on affected i

An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code execution on affected installations. Note that this vulnerability is similar to CVE-2025-49212 but is in a different method.

NVD description · AI analysis pending
9.8
group max
10%
  • trendmicro trend micro endpoint encryption
CVE-2025-48443
Trend Micro Password Manager (Consumer) version 5.0.0.1266 and below is vulnerable to a Link Following Local Privilege Escalation Vulnerability that could allow

Trend Micro Password Manager (Consumer) version 5.0.0.1266 and below is vulnerable to a Link Following Local Privilege Escalation Vulnerability that could allow a local attacker to leverage this vulnerability to delete files in the context of an administrator when the administrator installs Trend Micro Password Manager.

NVD description · AI analysis pending
6.6<1%
  • trendmicro password manager
CVE-2025-30641
+2 in the same advisory: …30640 …30642
A link following vulnerability in the anti-malware solution portion of Trend Micro Deep Security 20.0 agents could allow a local attacker to escalate privileges

A link following vulnerability in the anti-malware solution portion of Trend Micro Deep Security 20.0 agents could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

NVD description · AI analysis pending
7.8
group max
<1%
  • trendmicro deep security agent
CVE-2025-49220
+4 in the same advisory: …49219 …30678 …30679 …30680
An insecure deserialization operation in Trend Micro Apex Central below version 8.0.7007 could lead to a pre-authentication remote code execution on affected in

An insecure deserialization operation in Trend Micro Apex Central below version 8.0.7007 could lead to a pre-authentication remote code execution on affected installations. Note that this vulnerability is similar to CVE-2025-49219 but is in a different method.

NVD description · AI analysis pending
9.8
group max
2%
  • trendmicro apex central
CVE-2025-49487
An uncontrolled search path vulnerability in the Trend Micro Worry-Free Business Security Services (WFBSS) agent could have allowed an attacker with physical ac

An uncontrolled search path vulnerability in the Trend Micro Worry-Free Business Security Services (WFBSS) agent could have allowed an attacker with physical access to a machine to execute arbitrary code on affected installations. An attacker must have had physical access to the target system in order to exploit this vulnerability due to need to access a certain hardware component. Also note: this vulnerability only affected the SaaS client version of WFBSS only, meaning the on-premise version of Worry-Free Business Security was not affected, and this issue was addressed in a previous WFBSS monthly maintenance update. Therefore no other customer action is required to mitigate if the WFBSS agents are on the regular SaaS maintenance deployment schedule and this disclosure is for informational purposes only.

NVD description · AI analysis pending
6.8<1%
  • trendmicro worry-free business security services
CVE-2025-49155
+3 in the same advisory: …49157 …49158 …49156
An uncontrolled search path vulnerability in the Trend Micro Apex One Data Loss Prevention module could allow an attacker to inject malicious code leading to ar

An uncontrolled search path vulnerability in the Trend Micro Apex One Data Loss Prevention module could allow an attacker to inject malicious code leading to arbitrary code execution on affected installations.

NVD description · AI analysis pending
8.8
group max
<1%
  • trendmicro apex one
CVE-2025-49154
An insecure access control vulnerability in Trend Micro Apex One and Trend Micro Worry-Free Business Security could allow a local attacker to overwrite key memo

An insecure access control vulnerability in Trend Micro Apex One and Trend Micro Worry-Free Business Security could allow a local attacker to overwrite key memory-mapped files which could then have severe consequences for the security and stability of affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

NVD description · AI analysis pending
7.8<1%
  • trendmicro worry-free business security
  • trendmicro worry-free business security services
  • trendmicro apex one