Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
577 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.13% | — | Trendmicro Apex ONE | 21/5/2026 | 23/7/2026 | A time-of-check time-of-use vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. | |
| Analizada | Alta (7.8) | 0.10% | — | Trendmicro Apex ONE | 21/5/2026 | 23/7/2026 | An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affected installations. This is similar to CVE-2026-45206 but exists in a different process protection communication mechanism. Please note: an attacker must first obtain the ability to execute… | |
| Analizada | Alta (7.8) | 0.10% | — | Trendmicro Apex ONE | 21/5/2026 | 23/7/2026 | An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affected installations. This is similar to CVE-2026-45207 but exists in a different process protection communication mechanism. Please note: an attacker must first obtain the ability to execute… | |
| Analizada | Alta (7.8) | 0.10% | — | Trendmicro Apex ONE | 21/5/2026 | 23/7/2026 | An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affected installations. This is similar to CVE-2026-34927 but exists in a different process protection mechanism. Please note: an attacker must first obtain the ability to execute low-privileged code on… | |
| Analizada | Alta (7.8) | 0.10% | — | Trendmicro Apex ONE | 21/5/2026 | 23/7/2026 | An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affected installations. This is similar to CVE-2026-34927 but exists in a different inter-process communication mechanism. Please note: an attacker must first obtain the ability to execute low-privileged… | |
| Analizada | Alta (7.8) | 0.10% | — | Trendmicro Apex ONE | 21/5/2026 | 23/7/2026 | An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affected installations. This is similar to CVE-2026-34927 but exists in a different named pipe communication mechanism. Please note: an attacker must first obtain the ability to execute low-privileged… | |
| Analizada | Alta (7.8) | 0.10% | — | Trendmicro Apex ONE | 21/5/2026 | 23/7/2026 | An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. | |
| Analizada | Media (6.7) | 0.54% | ⚠ Explotación activa💥 PoC | Trendmicro Apex ONE | 21/5/2026 | 23/7/2026 | A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations. This vulnerability is only exploitable on the on-premise version of Apex One and a potential… | |
| Analizada | Alta (7.8) | 0.29% | — | Trendmicro Apex ONE | 21/5/2026 | 23/7/2026 | An origin validation error vulnerability in the Trend Micro Apex One (mac) agent self-protection mechanism could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this… | |
| Analizada | Alta (7.8) | 0.32% | — | Trendmicro Apex ONE | 21/5/2026 | 23/7/2026 | A time-of-check time-of-use vulnerability in the Trend Micro Apex One (mac) agent cache mechanism could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this… | |
| Analizada | Alta (7) | 0.30% | — | Trendmicro Apex ONE | 21/5/2026 | 23/7/2026 | A time-of-check time-of-use vulnerability in the Trend Micro Apex One (mac) agent iCore service signature verification could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to… | |
| Analizada | Alta (7.8) | 0.36% | — | Trendmicro Apex ONE | 21/5/2026 | 23/7/2026 | An origin validation error vulnerability in the Trend Micro Apex One (mac) agent iCore service could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this… | |
| Analizada | Alta (7.8) | 0.34% | — | Trendmicro Apex ONE | 21/5/2026 | 23/7/2026 | An origin validation error vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. | |
| Analizada | Alta (7.8) | 0.54% | — | Trendmicro Apex ONE | 21/5/2026 | 23/7/2026 | A link following vulnerability in the Trend Micro Apex One scan engine could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. | |
| Analizada | Crítica (9.8) | 3.8% | — | Trendmicro Apex ONE | 21/5/2026 | 23/7/2026 | A vulnerability in the Trend Micro Apex One management console could allow a remote attacker to upload malicious code and execute commands on affected installations. This vulnerability is similar in scope to CVE-2025-71210 but affects a different executable. Please note: although this vulnerability carries a technical… | |
| Analizada | Crítica (9.8) | 3.8% | — | Trendmicro Apex ONE | 21/5/2026 | 23/7/2026 | A vulnerability in the Trend Micro Apex One management console could allow a remote attacker to upload malicious code and execute commands on affected installations. Please note: although this vulnerability carries a technical critical CVSS rating, this was reported via responsible disclosure via a researcher through… | |
| Analizada | Alta (7.5) | 1.6% | — | Trendmicro Apex Central | 8/1/2026 | 7/10/2026 | A message out-of-bounds read vulnerability in Trend Micro Apex Central could allow a remote attacker to create a denial-of-service condition on affected installations. Please note: authentication is not required in order to exploit this vulnerability. | |
| Analizada | Alta (7.5) | 1.6% | — | Trendmicro Apex Central | 8/1/2026 | 7/10/2026 | A message unchecked NULL return value vulnerability in Trend Micro Apex Central could allow a remote attacker to create a denial-of-service condition on affected installations. Please note: authentication is not required in order to exploit this vulnerability.. | |
| Analizada | Crítica (9.8) | 3.6% | — | Trendmicro Apex Central | 8/1/2026 | 7/10/2026 | A LoadLibraryEX vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to load an attacker-controlled DLL into a key executable, leading to execution of attacker-supplied code under the context of SYSTEM on affected installations. | |
| Analizada | Crítica (9.8) | 20% | — | Trendmicro Apex ONE | 5/8/2025 | 17/6/2026 | A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious code and execute commands on affected installations. This vulnerability is essentially the same as CVE-2025-54948 but targets a different CPU architecture. | |
| Analizada | Crítica (9.8) | 24% | ⚠ Explotación activa | Trendmicro Apex ONE | 5/8/2025 | 17/6/2026 | A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious code and execute commands on affected installations. | |
| Analizada | Alta (7.8) | 0.24% | — | Trendmicro Cleaner ONE | 10/7/2025 | 17/6/2026 | Trend Micro Cleaner One Pro is vulnerable to a Privilege Escalation vulnerability that could allow a local attacker to unintentionally delete privileged Trend Micro files including its own. | |
| Analizada | Crítica (9.8) | 0.75% | — | Trendmicro Worry-free Business Security Services | 10/7/2025 | 17/6/2026 | A missing authentication vulnerability in Trend Micro Worry-Free Business Security Services (WFBSS) agent could have allowed an unauthenticated attacker to remotely take control of the agent on affected installations. Also note: this vulnerability only affected the SaaS client version of WFBSS only, meaning the… | |
| Analizada | Alta (7.8) | 0.17% | — | Trendmicro Password Manager | 10/7/2025 | 17/6/2026 | Trend Micro Password Manager (Consumer) version 5.8.0.1327 and below is vulnerable to a Link Following Privilege Escalation Vulnerability that could allow an attacker the opportunity to abuse symbolic links and other methods to delete any file/folder and achieve privilege escalation. | |
| Analizada | Alta (7.1) | 0.36% | — | Trendmicro Maximum Security 2022 | 10/7/2025 | 17/6/2026 | Trend Micro Security 17.8 (Consumer) is vulnerable to a link following local privilege escalation vulnerability that could allow a local attacker to unintentionally delete privileged Trend Micro files including its own. |