Endpoint security (EDR and XDR)

Trend Micro advisories: every record the registers tie to its products

In one line

69 advisories are attributed to Trend Micro products in this record, covering November 2021 to May 2026, and 11 of them appear in the CISA catalogue of known exploited vulnerabilities. A further 8 register entries mention Trend Micro without naming one of its products as affected, and are excluded rather than counted. Each entry below links to the register that published it.

Attributed

69

tied to a named product

Known exploited

11

in the CISA catalogue

Rated critical

18

by the register

Last checked

Jul 31, 2026

sources re-queried

Why this list is shorter than a CVE mirror

The registers are searched by keyword, so a search for a company name returns advisories that merely mention it. A mirror publishes those. This page does not: an entry appears only when the register itself ties it to a product of Trend Micro, through a reference on the vendor's own domain, the vendor named as the assigning authority, or the affected product list naming it.

8 entries did not clear that bar and are not shown. That is the difference, and it is deliberate: a page that lists another company's vulnerability under this heading is wrong in the way that matters most.

63 of the 69 records carry a CVSS base score from the register. Where none is published, none is shown, and no score is estimated.

The full list, most recently exploited and most recent first

Records held by several registers are folded into one entry with a link to each, so the same vulnerability is not counted twice. Entries listed in the CISA catalogue of known exploited vulnerabilities are shown first, because that is the one flag on this page that changes what a reader should do next.

  • CVE-2025-54948criticalKnown exploitedAug 18, 2025

    Trend Micro Apex One OS Command Injection Vulnerability

  • CVE-2023-41179criticalKnown exploitedSep 21, 2023

    Trend Micro Apex One and Worry-Free Business Security Remote Code Execution Vulnerability

  • CVE-2022-40139criticalKnown exploitedSep 15, 2022

    Trend Micro Apex One and Apex One as a Service Improper Validation Vulnerability

  • CVE-2022-26871criticalKnown exploitedMar 31, 2022

    Trend Micro Apex Central Arbitrary File Upload Vulnerability

  • CVE-2020-24557criticalCVSS 7.8Known exploitedNov 03, 2021

    Trend Micro Multiple Products Improper Access Control Vulnerability

  • CVE-2020-8468criticalCVSS 8.8Known exploitedNov 03, 2021

    Trend Micro Multiple Products Content Validation Escape Vulnerability

  • CVE-2021-36742criticalKnown exploitedNov 03, 2021

    Trend Micro Multiple Products Improper Input Validation Vulnerability

  • CVE-2021-36741criticalKnown exploitedNov 03, 2021

    Trend Micro Multiple Products Improper Input Validation Vulnerability

  • CVE-2020-8599criticalCVSS 9.8Known exploitedNov 03, 2021

    Trend Micro Apex One and OfficeScan Authentication Bypass Vulnerability

  • CVE-2020-8467criticalCVSS 8.8Known exploitedNov 03, 2021

    Trend Micro Apex One and OfficeScan Remote Code Execution Vulnerability

  • CVE-2019-18187criticalCVSS 8.8Known exploitedNov 03, 2021

    Trend Micro OfficeScan Directory Traversal Vulnerability

  • WID-SEC-2026-1643mediumCVSS 7.8May 29, 2026

    Affected products: Trend Micro Apex One

  • WID-SEC-2026-0509highCVSS 9.8May 22, 2026

    Affected products: Trend Micro Apex One

  • CVE-2026-45208highCVSS 7.8May 21, 2026

    A time-of-check time-of-use vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affected installations.

  • CVE-2026-45207highCVSS 7.8May 21, 2026

    An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affected installations.

  • CVE-2026-45206highCVSS 7.8May 21, 2026

    An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affected installations.

  • CVE-2026-34930highCVSS 7.8May 21, 2026

    An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affected installations.

  • CVE-2026-34929highCVSS 7.8May 21, 2026

    An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affected installations.

  • CVE-2026-34928highCVSS 7.8May 21, 2026

    An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affected installations.

  • CVE-2026-34927highCVSS 7.8May 21, 2026

    An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affected installations.

  • CVE-2026-34926mediumCVSS 6.7May 21, 2026

    A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy…

  • CVE-2025-71217highCVSS 7.8May 21, 2026

    An origin validation error vulnerability in the Trend Micro Apex One (mac) agent self-protection mechanism could allow a local attacker to escalate privileges on affected installations.

  • CVE-2025-71216highCVSS 7.8May 21, 2026

    A time-of-check time-of-use vulnerability in the Trend Micro Apex One (mac) agent cache mechanism could allow a local attacker to escalate privileges on affected installations.

  • CVE-2025-71215highCVSS 7.0May 21, 2026

    A time-of-check time-of-use vulnerability in the Trend Micro Apex One (mac) agent iCore service signature verification could allow a local attacker to escalate privileges on affected…

  • CVE-2025-71214highCVSS 7.8May 21, 2026

    An origin validation error vulnerability in the Trend Micro Apex One (mac) agent iCore service could allow a local attacker to escalate privileges on affected installations.

  • CVE-2025-71213highCVSS 7.8May 21, 2026

    An origin validation error vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations.

  • CVE-2025-71212highCVSS 7.8May 21, 2026

    A link following vulnerability in the Trend Micro Apex One scan engine could allow a local attacker to escalate privileges on affected installations.

  • CVE-2025-71211criticalCVSS 9.8May 21, 2026

    A vulnerability in the Trend Micro Apex One management console could allow a remote attacker to upload malicious code and execute commands on affected installations.

  • CVE-2025-71210criticalCVSS 9.8May 21, 2026

    A vulnerability in the Trend Micro Apex One management console could allow a remote attacker to upload malicious code and execute commands on affected installations.

  • WID-SEC-2026-0587highCVSS 8.1Mar 04, 2026

    Affected products: Trend Micro Apex Central

  • WID-SEC-2026-0043highCVSS 9.8Jan 09, 2026

    Affected products: Trend Micro Apex Central

  • CVE-2025-69260highCVSS 7.5Jan 08, 2026

    A message out-of-bounds read vulnerability in Trend Micro Apex Central could allow a remote attacker to create a denial-of-service condition on affected installations.

  • CVE-2025-69259highCVSS 7.5Jan 08, 2026

    A message unchecked NULL return value vulnerability in Trend Micro Apex Central could allow a remote attacker to create a denial-of-service condition on affected installations.

  • CVE-2025-69258criticalCVSS 9.8Jan 08, 2026

    A LoadLibraryEX vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to load an attacker-controlled DLL into a key executable, leading to execution of…

  • WID-SEC-2025-1727criticalCVSS 9.4Aug 22, 2025

    Affected products: Trend Micro Apex One

  • CVE-2025-54987criticalCVSS 9.4Aug 05, 2025

    A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious code and execute commands on affected…

  • WID-SEC-2025-1530mediumCVSS 7.6Jul 11, 2025

    Affected products: Trend Micro Worry-Free Business Security

  • WID-SEC-2025-1510mediumCVSS 7.0Jul 11, 2025

    Affected products: Trend Micro Maximum Security

  • CVE-2025-52837highCVSS 7.8Jul 10, 2025

    Trend Micro Password Manager (Consumer) version 5.8.0.1327 and below is vulnerable to a Link Following Privilege Escalation Vulnerability that could allow an attacker the opportunity to…

  • CVE-2025-52521highCVSS 7.8Jul 10, 2025

    Trend Micro Security 17.8 (Consumer) is vulnerable to a link following local privilege escalation vulnerability that could allow a local attacker to unintentionally delete privileged Trend…

  • CVE-2025-49218highCVSS 7.7Jun 17, 2025

    A post-auth SQL injection vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to escalate privileges on affected installations.

  • CVE-2025-49220criticalCVSS 9.8Jun 17, 2025

    An insecure deserialization operation in Trend Micro Apex Central below version 8.0.7007 could lead to a pre-authentication remote code execution on affected installations.

  • CVE-2025-49219criticalCVSS 9.8Jun 17, 2025

    An insecure deserialization operation in Trend Micro Apex Central below versions 8.0.7007 could lead to a pre-authentication remote code execution on affected installations.

  • CVE-2025-47867highCVSS 7.5Jun 17, 2025

    A Local File Inclusion vulnerability in a Trend Micro Apex Central widget in versions below 8.0.6955 could allow an attacker to include arbitrary files to execute as PHP code and lead to…

  • CVE-2025-47865highCVSS 7.5Jun 17, 2025

    A Local File Inclusion vulnerability in a Trend Micro Apex Central widget below version 8.0.6955 could allow an attacker to gain remote code execution on affected installations.

  • WID-SEC-2025-1292highCVSS 9.8Jun 11, 2025

    Affected products: Trend Micro Apex Central

  • WID-SEC-2025-1268highCVSS 8.8Jun 10, 2025

    Affected products: Trend Micro Apex One

  • WID-SEC-2025-1260mediumCVSS 7.8Jun 10, 2025

    Affected products: Trend Micro Internet Security

  • WID-SEC-2025-1259mediumCVSS 7.8Jun 10, 2025

    Affected products: Trend Micro Maximum Security

  • WID-SEC-2025-1255highCVSS 8.7Jun 10, 2025

    Affected products: Trend Micro Worry-Free Business Security

  • WID-SEC-2025-1121mediumCVSS 7.5May 22, 2025

    Affected products: Trend Micro Apex Central

  • CVE-2025-31285mediumCVSS 4.6Apr 02, 2025

    A broken access control vulnerability previously discovered in the Trend Vision One Role Name component could have allowed an administrator to create users who could then change the role of…

  • CVE-2025-31284mediumCVSS 4.6Apr 02, 2025

    A broken access control vulnerability previously discovered in the Trend Vision One Status component could have allowed an administrator to create users who could then change the role of…

  • CVE-2025-31283mediumCVSS 4.6Apr 02, 2025

    A broken access control vulnerability previously discovered in the Trend Vision One User Roles component could have allowed an administrator to create users who could then change the role…

  • CVE-2025-31282mediumCVSS 4.6Apr 02, 2025

    A broken access control vulnerability previously discovered in the Trend Vision One User Account component could have allowed an administrator to create users who could then change the role…

  • WID-SEC-2025-0677mediumCVSS 7.8Apr 02, 2025

    Affected products: Trend Micro Deep Security Agent

  • WID-SEC-2025-0674mediumCVSS 7.1Apr 02, 2025

    Affected products: Trend Micro Apex Central

  • WID-SEC-2024-3712mediumCVSS 7.8Mar 26, 2025

    Affected products: Trend Micro Apex One

  • CVE-2024-58105highCVSS 7.3Mar 25, 2025

    A vulnerability in the Trend Micro Apex One Security Agent Plug-in User Interface Manager could allow a local attacker to bypass existing security and execute arbitrary code on affected…

  • CVE-2024-58104highCVSS 7.3Mar 25, 2025

    A vulnerability in the Trend Micro Apex One Security Agent Plug-in User Interface Manager could allow a local attacker to bypass existing security and execute arbitrary code on affected…

  • WID-SEC-2025-0030mediumCVSS 7.5Jan 09, 2025

    Affected products: Trend Micro Apex One

  • WID-SEC-2024-3734mediumCVSS 6.7Dec 19, 2024

    Affected products: Trend Micro Deep Security Agent

  • WID-SEC-2024-3489highCVSS 8.0Nov 19, 2024

    Affected products: Trend Micro Deep Security Agent

  • WID-SEC-2024-3256highCVSS 8.4Oct 23, 2024

    Affected products: Trend Micro AntiVirus

  • WID-SEC-2024-3209mediumCVSS 7.8Oct 16, 2024

    Affected products: Trend Micro Deep Security Agent

  • WID-SEC-2024-2140mediumCVSS 6.5Sep 16, 2024

    Affected products: Trend Micro Deep Discovery Email Inspector

  • WID-SEC-2024-1537mediumCVSS 7.5Jul 08, 2024

    Affected products: Trend Micro Apex One

  • WID-SEC-2024-1256mediumCVSS 7.8Jun 07, 2024

    Affected products: Trend Micro Apex One

  • WID-SEC-2024-1257mediumCVSS 5.4May 31, 2024

    Affected products: Trend Micro InterScan Web Security Virtual Appliance

Which registers contributed

RegisterOperated byEntriesLatest
European Vulnerability DatabaseENISA, European Union42May 27, 2026
CERT-Bund security advisoriesBSI, Federal Republic of Germany29May 29, 2026
Known Exploited Vulnerabilities catalogueCISA, United States11Aug 18, 2025

The entry counts here are the raw register totals for Trend Micro, before attribution. They are larger than the list above for exactly that reason.

Questions this page answers

How many vulnerabilities does Trend Micro have?

69 advisories in this record are tied by a register to a product of Trend Micro. That is not the same as the number of vulnerabilities the products contain, and no public source knows that number. It is the count of what has been found, disclosed and published, which depends on how much the products are examined and how openly the vendor discloses.

Are any Trend Micro vulnerabilities being actively exploited?

11 of the 69 records here appear in the CISA catalogue of known exploited vulnerabilities, which lists flaws with confirmed exploitation in the wild. They are shown first in the list above. Whether any of them affects your deployment depends on the versions and components you run.

Why does this page show fewer CVEs for Trend Micro than other sites?

Because a keyword search for a company name returns advisories about other companies' products that mention it in passing, and this page excludes those. 8 register entries name Trend Micro without naming one of its products as affected. A mirror that lists them produces a longer page and a wrong number.

Where do the Trend Micro advisories on this page come from?

From European Vulnerability Database (ENISA, European Union); CERT-Bund security advisories (BSI, Federal Republic of Germany); Known Exploited Vulnerabilities catalogue (CISA, United States). Every entry links back to the register that published it, and carries the date that register states. Where the same vulnerability is held by several registers it is shown once with a link to each, rather than counted twice.

Does a long advisory list mean Trend Micro is insecure?

No. A register records what researchers found and what the vendor disclosed, so a widely deployed product with a working disclosure process accumulates more entries than one nobody examines. A short list can equally mean a small install base or a vendor that publishes little. This page reports the record and does not rate the vendor, because whether this is acceptable depends on your risk appetite, your compliance scope and the alternatives you are weighing.

A list of advisories is not a risk assessment

What matters is which of these touch the components you actually run, in the configuration you actually run them in, and whether that is acceptable next to the alternatives on your shortlist. DecisionOS reads the same pool against the criteria of a real decision and produces a memo that holds up in front of a board and an auditor.

The full Trend Micro record, including sources and open questions

Trend Micro vulnerabilities: all 69 advisories on record, with sources | DecisionOS by nexalign