CyberMax
Home › Exploited CVEs

Trend Micro known exploited vulnerabilities

CISA KEV catalog 2026.09.25 (1,726 CVEs) with FIRST EPSS scores from 2026-09-27.

CISA lists 12 Trend Micro CVEs as exploited in the wild. 1 were added in the last 12 months (latest 2026-05-21), and 0 are known to be used in ransomware campaigns.

Trend Micro CVEs added to CISA KEV per year
2021: 7202172022: 2202222023: 1202312025: 1202512026: 120261

Year = when CISA added the CVE to the catalog (KEV started in November 2021).

Patch first: highest EPSS right now

EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.

Most affected Trend Micro products

Apex One (2), Apex One, Apex One as a Service, and Worry-Free Business Security (2), Apex One and OfficeScan (2), Apex One and Worry-Free Business Security (1), Apex One and Apex One as a Service (1), Apex Central (1), Apex One, OfficeScan and Worry-Free Business Security Agents (1), Apex One, OfficeScan, and Worry-Free Business Security (1), OfficeScan (1).

All Trend Micro CVEs in KEV

CVEProductFlawAddedFederal dueEPSSRansomware
CVE-2026-34926Apex OneApex One (On-Premise) Directory Traversal2026-05-212026-06-040.5%–
CVE-2025-54948Apex OneApex One OS Command Injection2025-08-182025-09-0822.0%–
CVE-2023-41179Apex One and Worry-Free Business SecurityApex One and Worry-Free Business Security Remote Code Execution2023-09-212023-10-124.3%–
CVE-2022-40139Apex One and Apex One as a ServiceApex One and Apex One as a Service Improper Validation2022-09-152022-10-063.3%–
CVE-2022-26871Apex CentralApex Central Arbitrary File Upload2022-03-312022-04-2119.5%–
CVE-2021-36742Apex One, Apex One as a Service, and Worry-Free Business SecurityMultiple Products Improper Input Validation2021-11-032021-11-171.5%–
CVE-2021-36741Apex One, Apex One as a Service, and Worry-Free Business SecurityMultiple Products Improper Input Validation2021-11-032021-11-175.0%–
CVE-2020-8599Apex One and OfficeScanApex One and OfficeScan Authentication Bypass2021-11-032022-05-0311.9%–
CVE-2020-8468Apex One, OfficeScan and Worry-Free Business Security AgentsMultiple Products Content Validation Escape2021-11-032022-05-036.2%–
CVE-2020-8467Apex One and OfficeScanApex One and OfficeScan Remote Code Execution2021-11-032022-05-0310.9%–
CVE-2020-24557Apex One, OfficeScan, and Worry-Free Business SecurityMultiple Products Improper Access Control2021-11-032022-05-032.7%–
CVE-2019-18187OfficeScanOfficeScan Directory Traversal2021-11-032022-05-0325.1%–
Federal due dates bind US federal civilian agencies (CISA binding operational directives); everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.

Read next: Which CVEs to patch first this week · All vendors