Trend Micro known exploited vulnerabilities
CISA lists 12 Trend Micro CVEs as exploited in the wild. 1 were added in the last 12 months (latest 2026-05-21), and 0 are known to be used in ransomware campaigns.
Year = when CISA added the CVE to the catalog (KEV started in November 2021).
Patch first: highest EPSS right now
EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.
- CVE-2019-18187 (OfficeScan): EPSS 25.1%, added 2021-11-03
- CVE-2025-54948 (Apex One): EPSS 22.0%, added 2025-08-18
- CVE-2022-26871 (Apex Central): EPSS 19.5%, added 2022-03-31
- CVE-2020-8599 (Apex One and OfficeScan): EPSS 11.9%, added 2021-11-03
- CVE-2020-8467 (Apex One and OfficeScan): EPSS 10.9%, added 2021-11-03
Most affected Trend Micro products
Apex One (2), Apex One, Apex One as a Service, and Worry-Free Business Security (2), Apex One and OfficeScan (2), Apex One and Worry-Free Business Security (1), Apex One and Apex One as a Service (1), Apex Central (1), Apex One, OfficeScan and Worry-Free Business Security Agents (1), Apex One, OfficeScan, and Worry-Free Business Security (1), OfficeScan (1).
All Trend Micro CVEs in KEV
| CVE | Product | Flaw | Added | Federal due | EPSS | Ransomware |
|---|---|---|---|---|---|---|
| CVE-2026-34926 | Apex One | Apex One (On-Premise) Directory Traversal | 2026-05-21 | 2026-06-04 | 0.5% | – |
| CVE-2025-54948 | Apex One | Apex One OS Command Injection | 2025-08-18 | 2025-09-08 | 22.0% | – |
| CVE-2023-41179 | Apex One and Worry-Free Business Security | Apex One and Worry-Free Business Security Remote Code Execution | 2023-09-21 | 2023-10-12 | 4.3% | – |
| CVE-2022-40139 | Apex One and Apex One as a Service | Apex One and Apex One as a Service Improper Validation | 2022-09-15 | 2022-10-06 | 3.3% | – |
| CVE-2022-26871 | Apex Central | Apex Central Arbitrary File Upload | 2022-03-31 | 2022-04-21 | 19.5% | – |
| CVE-2021-36742 | Apex One, Apex One as a Service, and Worry-Free Business Security | Multiple Products Improper Input Validation | 2021-11-03 | 2021-11-17 | 1.5% | – |
| CVE-2021-36741 | Apex One, Apex One as a Service, and Worry-Free Business Security | Multiple Products Improper Input Validation | 2021-11-03 | 2021-11-17 | 5.0% | – |
| CVE-2020-8599 | Apex One and OfficeScan | Apex One and OfficeScan Authentication Bypass | 2021-11-03 | 2022-05-03 | 11.9% | – |
| CVE-2020-8468 | Apex One, OfficeScan and Worry-Free Business Security Agents | Multiple Products Content Validation Escape | 2021-11-03 | 2022-05-03 | 6.2% | – |
| CVE-2020-8467 | Apex One and OfficeScan | Apex One and OfficeScan Remote Code Execution | 2021-11-03 | 2022-05-03 | 10.9% | – |
| CVE-2020-24557 | Apex One, OfficeScan, and Worry-Free Business Security | Multiple Products Improper Access Control | 2021-11-03 | 2022-05-03 | 2.7% | – |
| CVE-2019-18187 | OfficeScan | OfficeScan Directory Traversal | 2021-11-03 | 2022-05-03 | 25.1% | – |
Federal due dates bind US federal civilian agencies (CISA binding operational directives); everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.
Read next: Which CVEs to patch first this week · All vendors