{"record":"Trend Micro evidence record","url":"https://nexalign.io/vendors/trend-micro","vendor":{"slug":"trend-micro","name":"Trend Micro","domain":"trendmicro.com","category":"endpoint-security","categoryLabel":"Endpoint security (EDR and XDR)"},"lastChecked":"2026-07-31T10:17:54.127Z","coverage":{"earliest":"2019-10-28T19:28:32.000Z","latest":"2026-07-31T10:17:54.127Z"},"terms":{"isRanking":false,"isRating":false,"statesSuitability":false,"note":"This is a record of what public sources hold about a named company. It states no ranking, no rating and no suitability verdict, and none may be derived from it. An absent or small record means the public registers publish little under that name; it is not evidence that a product is secure. A larger advisory count generally reflects wider deployment and more scrutiny rather than a weaker product.","licence":"https://nexalign.io/vendors#licence","corrections":"info@nexalign.io"},"totals":{"evidenceItems":91,"kindsOfSource":6,"attributedAdvisories":69,"knownExploited":11,"registerEntriesNotAttributable":8,"practitionerThreads":3,"independentItems":4,"vendorPublishedItems":0,"shareFromSourcesTheVendorDoesNotControl":1},"sources":[{"source":"European Vulnerability Database","operator":"ENISA, European Union","classification":"authoritative","items":42,"latest":"2026-05-27T12:17:48.000Z"},{"source":"CERT-Bund security advisories","operator":"BSI, Federal Republic of Germany","classification":"authoritative","items":29,"latest":"2026-05-29T07:10:37.614Z"},{"source":"Known Exploited Vulnerabilities catalogue","operator":"CISA, United States","classification":"authoritative","items":11,"latest":"2025-08-18T00:00:00.000Z"},{"source":"Analyst, review and reference sources","operator":"Recognised analysts, review marketplaces and technology press","classification":"independent","items":4,"latest":"2026-07-31T10:17:54.127Z"},{"source":"Practitioner discussions","operator":"Reddit, public threads","classification":"independent","items":4,"latest":"2026-03-23T17:11:26.000Z"},{"source":"Engineering discussions","operator":"Hacker News, public threads","classification":"independent","items":1,"latest":"2026-01-04T18:45:35.000Z"}],"advisories":{"shown":6,"total":69,"truncated":true,"fullList":"https://nexalign.io/vendors/trend-micro/advisories","items":[{"id":"CVE-2025-54948","description":"Trend Micro Apex One OS Command Injection Vulnerability","severity":"critical","cvss":null,"knownExploited":true,"date":"2025-08-18T00:00:00.000Z","sources":["https://nvd.nist.gov/vuln/detail/CVE-2025-54948"]},{"id":"CVE-2023-41179","description":"Trend Micro Apex One and Worry-Free Business Security Remote Code Execution Vulnerability","severity":"critical","cvss":null,"knownExploited":true,"date":"2023-09-21T00:00:00.000Z","sources":["https://nvd.nist.gov/vuln/detail/CVE-2023-41179"]},{"id":"CVE-2022-40139","description":"Trend Micro Apex One and Apex One as a Service Improper Validation Vulnerability","severity":"critical","cvss":null,"knownExploited":true,"date":"2022-09-15T00:00:00.000Z","sources":["https://nvd.nist.gov/vuln/detail/CVE-2022-40139"]},{"id":"CVE-2022-26871","description":"Trend Micro Apex Central Arbitrary File Upload Vulnerability","severity":"critical","cvss":null,"knownExploited":true,"date":"2022-03-31T00:00:00.000Z","sources":["https://nvd.nist.gov/vuln/detail/CVE-2022-26871"]},{"id":"CVE-2020-24557","description":"Trend Micro Multiple Products Improper Access Control Vulnerability","severity":"critical","cvss":7.8,"knownExploited":true,"date":"2021-11-03T00:00:00.000Z","sources":["https://nvd.nist.gov/vuln/detail/CVE-2020-24557","https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-17276"]},{"id":"CVE-2020-8468","description":"Trend Micro Multiple Products Content Validation Escape Vulnerability","severity":"critical","cvss":8.8,"knownExploited":true,"date":"2021-11-03T00:00:00.000Z","sources":["https://nvd.nist.gov/vuln/detail/CVE-2020-8468","https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-29334"]}]},"practitionerThreads":{"shown":3,"total":3,"truncated":false,"items":[{"title":"Trend Micro's Enterprise Business is now TrendAI™… thoughts?","context":"r/cybersecurity","url":"https://www.reddit.com/r/cybersecurity/comments/1s1mxy3/trend_micros_enterprise_business_is_now_trendai/","date":"2026-03-23T17:11:26.000Z"},{"title":"Sanity Check- Trend Micro Worry-Free Business Security Services, Win11 24H2/25H2","context":"r/sysadmin","url":"https://www.reddit.com/r/sysadmin/comments/1qxtbmw/sanity_check_trend_micro_worryfree_business/","date":"2026-02-06T20:43:15.000Z"},{"title":"Need help choosing (trend micro vs CrowdStrike Vs FieldEffect)","context":"r/cybersecurity","url":"https://www.reddit.com/r/cybersecurity/comments/1qk453f/need_help_choosing_trend_micro_vs_crowdstrike_vs/","date":"2026-01-22T19:28:06.000Z"}]},"independentCoverage":{"shown":4,"total":4,"truncated":false,"items":[{"title":"Trend Micro Reviews, Ratings & Features 2023 | Gartner Peer Insights","host":"gartner.com","url":"https://www.gartner.com/reviews/market/cloud-native-application-protection-platforms/vendor/trend-micro","date":null},{"title":"Trend Micro - Wikipedia","host":"en.wikipedia.org","url":"https://en.wikipedia.org/wiki/Trend_Micro","date":null},{"title":"Trend Micro Reviews, Ratings & Features 2026 | Gartner Peer Insights","host":"gartner.com","url":"https://www.gartner.com/reviews/market/network-detection-and-response/vendor/trend-micro","date":null},{"title":"Trend Micro Reviews, Ratings & Features 2026 | Gartner Peer Insights","host":"gartner.com","url":"https://www.gartner.com/reviews/market/endpoint-protection-platforms/vendor/trend-micro","date":null}]},"vendorPublished":{"shown":0,"total":0,"truncated":false,"items":[]},"openQuestions":["A further 8 register entries mention Trend Micro without naming a product of Trend Micro as affected. They are excluded rather than counted as vulnerabilities.","Pricing, contract terms, notice periods and support commitments are not part of any public register. They come from the vendor and belong in a negotiation record.","Certification status such as ISO 27001, SOC 2 or BSI C5 has to be checked against the current certificate and its stated scope. A valid certificate can still exclude the product being bought."]}