Endpoint Security (EDR und XDR)
Schwachstellen bei Trend Micro: jede Meldung, die die Register seinen Produkten zuordnen
Kurz gesagt
69 Schwachstellenmeldungen in diesem Bestand sind Produkten von Trend Micro zugeordnet. Sie reichen von November 2021 bis Mai 2026. 11 davon stehen im CISA-Katalog bekannt ausgenutzter Schwachstellen. Weitere 8 Registereinträge nennen Trend Micro, ohne eines seiner Produkte als betroffen zu benennen, und bleiben deshalb außen vor, statt mitgezählt zu werden. Jeder Eintrag unten verlinkt auf das Register, das ihn veröffentlicht hat.
Zugeordnet
69
an ein benanntes Produkt gebunden
Aktiv ausgenutzt
11
im CISA-Katalog geführt
Als kritisch eingestuft
18
Einstufung des Registers
Zuletzt geprüft
31. Juli 2026
Quellen neu abgefragt
Warum diese Liste kürzer ist als ein CVE-Spiegel
Die Register werden über Stichworte durchsucht, also liefert die Suche nach einem Firmennamen auch Meldungen zurück, die diesen Namen nur erwähnen. Ein Spiegel veröffentlicht sie mit. Diese Seite nicht: Ein Eintrag erscheint erst, wenn das Register selbst ihn an ein Produkt von Trend Micro bindet, über einen Verweis auf eine Adresse des Anbieters, über Trend Micro als die Stelle, die die CVE-Nummer vergeben hat, oder über die Liste der betroffenen Produkte.
8 Einträge haben diese Hürde nicht genommen und werden nicht angezeigt. Das ist der Unterschied, und er ist gewollt: Eine Seite, die die Schwachstelle eines anderen Unternehmens unter dieser Überschrift führt, ist auf die Art falsch, die am meisten kostet.
63 der 69 Einträge tragen einen CVSS-Basiswert aus dem Register. Wo keiner veröffentlicht ist, steht keiner, und geschätzt wird nichts.
Die vollständige Liste, bekannt ausgenutzte und neueste zuerst
Führen mehrere Register dieselbe Meldung, steht sie einmal da, mit einem Link auf jedes. So wird dieselbe Schwachstelle nicht doppelt gezählt. Einträge aus dem CISA-Katalog bekannt ausgenutzter Schwachstellen stehen oben, weil das der eine Hinweis auf dieser Seite ist, der ändert, was als Nächstes zu tun ist.
- CVE-2025-54948criticalAktiv ausgenutzt18. Aug. 2025
Trend Micro Apex One OS Command Injection Vulnerability
- CVE-2023-41179criticalAktiv ausgenutzt21. Sept. 2023
Trend Micro Apex One and Worry-Free Business Security Remote Code Execution Vulnerability
- CVE-2022-40139criticalAktiv ausgenutzt15. Sept. 2022
Trend Micro Apex One and Apex One as a Service Improper Validation Vulnerability
- CVE-2022-26871criticalAktiv ausgenutzt31. März 2022
Trend Micro Apex Central Arbitrary File Upload Vulnerability
- CVE-2020-24557criticalCVSS 7.8Aktiv ausgenutzt03. Nov. 2021
Trend Micro Multiple Products Improper Access Control Vulnerability
- CVE-2020-8468criticalCVSS 8.8Aktiv ausgenutzt03. Nov. 2021
Trend Micro Multiple Products Content Validation Escape Vulnerability
- CVE-2021-36742criticalAktiv ausgenutzt03. Nov. 2021
Trend Micro Multiple Products Improper Input Validation Vulnerability
- CVE-2021-36741criticalAktiv ausgenutzt03. Nov. 2021
Trend Micro Multiple Products Improper Input Validation Vulnerability
- CVE-2020-8599criticalCVSS 9.8Aktiv ausgenutzt03. Nov. 2021
Trend Micro Apex One and OfficeScan Authentication Bypass Vulnerability
- CVE-2020-8467criticalCVSS 8.8Aktiv ausgenutzt03. Nov. 2021
Trend Micro Apex One and OfficeScan Remote Code Execution Vulnerability
- CVE-2019-18187criticalCVSS 8.8Aktiv ausgenutzt03. Nov. 2021
Trend Micro OfficeScan Directory Traversal Vulnerability
- WID-SEC-2026-1643mediumCVSS 7.829. Mai 2026
Affected products: Trend Micro Apex One
- WID-SEC-2026-0509highCVSS 9.822. Mai 2026
Affected products: Trend Micro Apex One
- CVE-2026-45208highCVSS 7.821. Mai 2026
A time-of-check time-of-use vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affected installations.
- CVE-2026-45207highCVSS 7.821. Mai 2026
An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affected installations.
- CVE-2026-45206highCVSS 7.821. Mai 2026
An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affected installations.
- CVE-2026-34930highCVSS 7.821. Mai 2026
An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affected installations.
- CVE-2026-34929highCVSS 7.821. Mai 2026
An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affected installations.
- CVE-2026-34928highCVSS 7.821. Mai 2026
An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affected installations.
- CVE-2026-34927highCVSS 7.821. Mai 2026
An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affected installations.
- CVE-2026-34926mediumCVSS 6.721. Mai 2026
A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy…
- CVE-2025-71217highCVSS 7.821. Mai 2026
An origin validation error vulnerability in the Trend Micro Apex One (mac) agent self-protection mechanism could allow a local attacker to escalate privileges on affected installations.
- CVE-2025-71216highCVSS 7.821. Mai 2026
A time-of-check time-of-use vulnerability in the Trend Micro Apex One (mac) agent cache mechanism could allow a local attacker to escalate privileges on affected installations.
- CVE-2025-71215highCVSS 7.021. Mai 2026
A time-of-check time-of-use vulnerability in the Trend Micro Apex One (mac) agent iCore service signature verification could allow a local attacker to escalate privileges on affected…
- CVE-2025-71214highCVSS 7.821. Mai 2026
An origin validation error vulnerability in the Trend Micro Apex One (mac) agent iCore service could allow a local attacker to escalate privileges on affected installations.
- CVE-2025-71213highCVSS 7.821. Mai 2026
An origin validation error vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations.
- CVE-2025-71212highCVSS 7.821. Mai 2026
A link following vulnerability in the Trend Micro Apex One scan engine could allow a local attacker to escalate privileges on affected installations.
- CVE-2025-71211criticalCVSS 9.821. Mai 2026
A vulnerability in the Trend Micro Apex One management console could allow a remote attacker to upload malicious code and execute commands on affected installations.
- CVE-2025-71210criticalCVSS 9.821. Mai 2026
A vulnerability in the Trend Micro Apex One management console could allow a remote attacker to upload malicious code and execute commands on affected installations.
- WID-SEC-2026-0587highCVSS 8.104. März 2026
Affected products: Trend Micro Apex Central
- WID-SEC-2026-0043highCVSS 9.809. Jan. 2026
Affected products: Trend Micro Apex Central
- CVE-2025-69260highCVSS 7.508. Jan. 2026
A message out-of-bounds read vulnerability in Trend Micro Apex Central could allow a remote attacker to create a denial-of-service condition on affected installations.
- CVE-2025-69259highCVSS 7.508. Jan. 2026
A message unchecked NULL return value vulnerability in Trend Micro Apex Central could allow a remote attacker to create a denial-of-service condition on affected installations.
- CVE-2025-69258criticalCVSS 9.808. Jan. 2026
A LoadLibraryEX vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to load an attacker-controlled DLL into a key executable, leading to execution of…
- WID-SEC-2025-1727criticalCVSS 9.422. Aug. 2025
Affected products: Trend Micro Apex One
- CVE-2025-54987criticalCVSS 9.405. Aug. 2025
A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious code and execute commands on affected…
- WID-SEC-2025-1530mediumCVSS 7.611. Juli 2025
Affected products: Trend Micro Worry-Free Business Security
- WID-SEC-2025-1510mediumCVSS 7.011. Juli 2025
Affected products: Trend Micro Maximum Security
- CVE-2025-52837highCVSS 7.810. Juli 2025
Trend Micro Password Manager (Consumer) version 5.8.0.1327 and below is vulnerable to a Link Following Privilege Escalation Vulnerability that could allow an attacker the opportunity to…
- CVE-2025-52521highCVSS 7.810. Juli 2025
Trend Micro Security 17.8 (Consumer) is vulnerable to a link following local privilege escalation vulnerability that could allow a local attacker to unintentionally delete privileged Trend…
- CVE-2025-49218highCVSS 7.717. Juni 2025
A post-auth SQL injection vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to escalate privileges on affected installations.
- CVE-2025-49220criticalCVSS 9.817. Juni 2025
An insecure deserialization operation in Trend Micro Apex Central below version 8.0.7007 could lead to a pre-authentication remote code execution on affected installations.
- CVE-2025-49219criticalCVSS 9.817. Juni 2025
An insecure deserialization operation in Trend Micro Apex Central below versions 8.0.7007 could lead to a pre-authentication remote code execution on affected installations.
- CVE-2025-47867highCVSS 7.517. Juni 2025
A Local File Inclusion vulnerability in a Trend Micro Apex Central widget in versions below 8.0.6955 could allow an attacker to include arbitrary files to execute as PHP code and lead to…
- CVE-2025-47865highCVSS 7.517. Juni 2025
A Local File Inclusion vulnerability in a Trend Micro Apex Central widget below version 8.0.6955 could allow an attacker to gain remote code execution on affected installations.
- WID-SEC-2025-1292highCVSS 9.811. Juni 2025
Affected products: Trend Micro Apex Central
- WID-SEC-2025-1268highCVSS 8.810. Juni 2025
Affected products: Trend Micro Apex One
- WID-SEC-2025-1260mediumCVSS 7.810. Juni 2025
Affected products: Trend Micro Internet Security
- WID-SEC-2025-1259mediumCVSS 7.810. Juni 2025
Affected products: Trend Micro Maximum Security
- WID-SEC-2025-1255highCVSS 8.710. Juni 2025
Affected products: Trend Micro Worry-Free Business Security
- WID-SEC-2025-1121mediumCVSS 7.522. Mai 2025
Affected products: Trend Micro Apex Central
- CVE-2025-31285mediumCVSS 4.602. Apr. 2025
A broken access control vulnerability previously discovered in the Trend Vision One Role Name component could have allowed an administrator to create users who could then change the role of…
- CVE-2025-31284mediumCVSS 4.602. Apr. 2025
A broken access control vulnerability previously discovered in the Trend Vision One Status component could have allowed an administrator to create users who could then change the role of…
- CVE-2025-31283mediumCVSS 4.602. Apr. 2025
A broken access control vulnerability previously discovered in the Trend Vision One User Roles component could have allowed an administrator to create users who could then change the role…
- CVE-2025-31282mediumCVSS 4.602. Apr. 2025
A broken access control vulnerability previously discovered in the Trend Vision One User Account component could have allowed an administrator to create users who could then change the role…
- WID-SEC-2025-0677mediumCVSS 7.802. Apr. 2025
Affected products: Trend Micro Deep Security Agent
- WID-SEC-2025-0674mediumCVSS 7.102. Apr. 2025
Affected products: Trend Micro Apex Central
- WID-SEC-2024-3712mediumCVSS 7.826. März 2025
Affected products: Trend Micro Apex One
- CVE-2024-58105highCVSS 7.325. März 2025
A vulnerability in the Trend Micro Apex One Security Agent Plug-in User Interface Manager could allow a local attacker to bypass existing security and execute arbitrary code on affected…
- CVE-2024-58104highCVSS 7.325. März 2025
A vulnerability in the Trend Micro Apex One Security Agent Plug-in User Interface Manager could allow a local attacker to bypass existing security and execute arbitrary code on affected…
- WID-SEC-2025-0030mediumCVSS 7.509. Jan. 2025
Affected products: Trend Micro Apex One
- WID-SEC-2024-3734mediumCVSS 6.719. Dez. 2024
Affected products: Trend Micro Deep Security Agent
- WID-SEC-2024-3489highCVSS 8.019. Nov. 2024
Affected products: Trend Micro Deep Security Agent
- WID-SEC-2024-3256highCVSS 8.423. Okt. 2024
Affected products: Trend Micro AntiVirus
- WID-SEC-2024-3209mediumCVSS 7.816. Okt. 2024
Affected products: Trend Micro Deep Security Agent
- WID-SEC-2024-2140mediumCVSS 6.516. Sept. 2024
Affected products: Trend Micro Deep Discovery Email Inspector
- WID-SEC-2024-1537mediumCVSS 7.508. Juli 2024
Affected products: Trend Micro Apex One
- WID-SEC-2024-1256mediumCVSS 7.807. Juni 2024
Affected products: Trend Micro Apex One
- WID-SEC-2024-1257mediumCVSS 5.431. Mai 2024
Affected products: Trend Micro InterScan Web Security Virtual Appliance
Welche Register beigetragen haben
| Register | Betreiber | Einträge | Neuester Eintrag |
|---|---|---|---|
| European Vulnerability Database | ENISA, Europäische Union | 42 | 27. Mai 2026 |
| CERT-Bund Sicherheitshinweise | BSI, Bundesrepublik Deutschland | 29 | 29. Mai 2026 |
| Katalog bekannt ausgenutzter Schwachstellen | CISA, Vereinigte Staaten | 11 | 18. Aug. 2025 |
Die Zahlen hier sind die rohen Registertreffer zu Trend Micro, vor der Zuordnung. Genau deshalb sind sie größer als die Liste darüber.
Fragen, die diese Seite beantwortet
Wie viele Schwachstellen hat Trend Micro?
69 Meldungen in diesem Bestand sind von einem Register einem Produkt von Trend Micro zugeordnet. Das ist nicht dasselbe wie die Zahl der Schwachstellen in den Produkten, und die kennt keine öffentliche Quelle. Es ist die Zahl dessen, was gefunden, offengelegt und veröffentlicht wurde, und die hängt daran, wie intensiv die Produkte geprüft werden und wie offen der Anbieter damit umgeht.
Werden Schwachstellen in Produkten von Trend Micro aktiv ausgenutzt?
11 der 69 Einträge stehen im CISA-Katalog bekannt ausgenutzter Schwachstellen, der Lücken mit bestätigter Ausnutzung in freier Wildbahn führt. Sie stehen in der Liste oben. Ob einer davon Ihre Installation betrifft, hängt an den Versionen und Komponenten, die Sie betreiben.
Warum zeigt diese Seite weniger CVEs zu Trend Micro als andere Seiten?
Weil eine Stichwortsuche nach einem Firmennamen auch Meldungen über Produkte anderer Unternehmen zurückgibt, die den Namen nur nebenbei erwähnen. Diese Seite lässt sie weg. 8 Registereinträge nennen Trend Micro, ohne eines seiner Produkte als betroffen zu benennen. Ein Spiegel, der sie mitführt, erzeugt eine längere Seite und eine falsche Zahl.
Woher stammen die Meldungen zu Trend Micro auf dieser Seite?
Aus diesen Registern: European Vulnerability Database, betrieben von ENISA, Europäische Union; CERT-Bund Sicherheitshinweise, betrieben von BSI, Bundesrepublik Deutschland; Katalog bekannt ausgenutzter Schwachstellen, betrieben von CISA, Vereinigte Staaten. Jeder Eintrag verlinkt zurück auf das Register, das ihn veröffentlicht hat, und trägt das Datum, das dieses Register nennt. Führen mehrere Register dieselbe Schwachstelle, steht sie einmal da, mit einem Link auf jedes, statt doppelt gezählt zu werden.
Heißt eine lange Liste, dass Trend Micro unsicher ist?
Nein. Ein Register hält fest, was Forschende gefunden und was der Anbieter offengelegt hat. Ein weit verbreitetes Produkt mit einem funktionierenden Offenlegungsprozess sammelt deshalb mehr Einträge als eines, das niemand prüft. Eine kurze Liste kann genauso gut für eine kleine Installationsbasis stehen oder für einen Anbieter, der wenig veröffentlicht. Diese Seite gibt den Bestand wieder und bewertet den Anbieter nicht, denn ob das für Sie tragbar ist, hängt an Ihrer Risikobereitschaft, Ihrem Compliance-Umfang und den Alternativen, die Sie abwägen.
Eine Liste von Meldungen ist noch keine Risikobewertung
Es zählt, welche davon die Komponenten betreffen, die Sie tatsächlich betreiben, in der Konfiguration, in der Sie sie betreiben, und ob das neben den Alternativen Ihrer engeren Auswahl tragbar ist. DecisionOS liest denselben Bestand an den Kriterien einer konkreten Entscheidung und liefert ein Memo, das vor Geschäftsführung und Revision standhält.
Der vollständige Bestand zu Trend Micro, samt Quellen und offenen Fragen
