How we count
Every figure on this page is a direct count of entries in CISA’s Known Exploited Vulnerabilities catalog attributed by CISA to Trend Micro (KEV field vendorProject), refreshed daily. “Ransomware-linked” counts entries CISA marks as known to be used in ransomware campaigns; the remainder are “unknown” to CISA, not confirmed ransomware-free. A KEV listing means the vulnerability has been observed exploited in the wild. Snapshot as of 2026-08-31.
Exploited Trend Micro vulnerabilities (CISA KEV)
| CVE | Product | Vulnerability | Added | |
|---|---|---|---|---|
| CVE-2026-34926 | Apex One | Trend Micro Apex One (On-Premise) Directory Traversal Vulnerability | 2026-05-21 | |
| CVE-2025-54948 | Apex One | Trend Micro Apex One OS Command Injection Vulnerability | 2025-08-18 | |
| CVE-2023-41179 | Apex One and Worry-Free Business Security | Trend Micro Apex One and Worry-Free Business Security Remote Code Execution Vulnerability | 2023-09-21 | |
| CVE-2022-40139 | Apex One and Apex One as a Service | Trend Micro Apex One and Apex One as a Service Improper Validation Vulnerability | 2022-09-15 | |
| CVE-2022-26871 | Apex Central | Trend Micro Apex Central Arbitrary File Upload Vulnerability | 2022-03-31 | |
| CVE-2019-18187 | OfficeScan | Trend Micro OfficeScan Directory Traversal Vulnerability | 2021-11-03 | |
| CVE-2020-8467 | Apex One and OfficeScan | Trend Micro Apex One and OfficeScan Remote Code Execution Vulnerability | 2021-11-03 | |
| CVE-2020-8468 | Apex One, OfficeScan and Worry-Free Business Security Agents | Trend Micro Multiple Products Content Validation Escape Vulnerability | 2021-11-03 | |
| CVE-2020-24557 | Apex One, OfficeScan, and Worry-Free Business Security | Trend Micro Multiple Products Improper Access Control Vulnerability | 2021-11-03 | |
| CVE-2020-8599 | Apex One and OfficeScan | Trend Micro Apex One and OfficeScan Authentication Bypass Vulnerability | 2021-11-03 | |
| CVE-2021-36742 | Apex One, Apex One as a Service, and Worry-Free Business Security | Trend Micro Multiple Products Improper Input Validation Vulnerability | 2021-11-03 | |
| CVE-2021-36741 | Apex One, Apex One as a Service, and Worry-Free Business Security | Trend Micro Multiple Products Improper Input Validation Vulnerability | 2021-11-03 |
← All vendors by exploited-vulnerability count
🤖 Generated by defend.network from the CISA KEV catalog. Counts are deterministic aggregates of official CISA data; verify individual advisories at the linked sources.