Vendor Exploitation Record

Trend Micro (Apex One) — Known Exploited Vulnerabilities

12 in CISA KEV · 0 ransomware-linked · as of 2026-08-31
In CISA KEV12 confirmed exploited
Ransomware-linked0 (0% of KEV, per CISA)
First KEV addition2021-11-03
Most recent2026-05-21

How we count

Every figure on this page is a direct count of entries in CISA’s Known Exploited Vulnerabilities catalog attributed by CISA to Trend Micro (KEV field vendorProject), refreshed daily. “Ransomware-linked” counts entries CISA marks as known to be used in ransomware campaigns; the remainder are “unknown” to CISA, not confirmed ransomware-free. A KEV listing means the vulnerability has been observed exploited in the wild. Snapshot as of 2026-08-31.

Exploited Trend Micro vulnerabilities (CISA KEV)

CVEProductVulnerabilityAdded
CVE-2026-34926Apex OneTrend Micro Apex One (On-Premise) Directory Traversal Vulnerability2026-05-21
CVE-2025-54948Apex OneTrend Micro Apex One OS Command Injection Vulnerability2025-08-18
CVE-2023-41179Apex One and Worry-Free Business SecurityTrend Micro Apex One and Worry-Free Business Security Remote Code Execution Vulnerability2023-09-21
CVE-2022-40139Apex One and Apex One as a ServiceTrend Micro Apex One and Apex One as a Service Improper Validation Vulnerability2022-09-15
CVE-2022-26871Apex CentralTrend Micro Apex Central Arbitrary File Upload Vulnerability2022-03-31
CVE-2019-18187OfficeScanTrend Micro OfficeScan Directory Traversal Vulnerability2021-11-03
CVE-2020-8467Apex One and OfficeScanTrend Micro Apex One and OfficeScan Remote Code Execution Vulnerability2021-11-03
CVE-2020-8468Apex One, OfficeScan and Worry-Free Business Security AgentsTrend Micro Multiple Products Content Validation Escape Vulnerability2021-11-03
CVE-2020-24557Apex One, OfficeScan, and Worry-Free Business SecurityTrend Micro Multiple Products Improper Access Control Vulnerability2021-11-03
CVE-2020-8599Apex One and OfficeScanTrend Micro Apex One and OfficeScan Authentication Bypass Vulnerability2021-11-03
CVE-2021-36742Apex One, Apex One as a Service, and Worry-Free Business SecurityTrend Micro Multiple Products Improper Input Validation Vulnerability2021-11-03
CVE-2021-36741Apex One, Apex One as a Service, and Worry-Free Business SecurityTrend Micro Multiple Products Improper Input Validation Vulnerability2021-11-03

← All vendors by exploited-vulnerability count

🤖 Generated by defend.network from the CISA KEV catalog. Counts are deterministic aggregates of official CISA data; verify individual advisories at the linked sources.

Track newly exploited vulnerabilities

Free daily briefing on CVEs added to CISA KEV and exploited in the wild.