Trendmicro
Trendmicro Apex ONE: vulnerabilidades y CVE
Trendmicro Apex ONE tiene 180 vulnerabilidades publicadas, 16 de ellas en los últimos 12 meses. 13 son críticas y 11 figuran en el catálogo de explotación activa de CISA.
CVE180
Últimos 12 meses16
Críticas13
Explotadas activamente11
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-34926 | Media (6.7) | 0.54% | ⚠ Explotación activa | 21 may 2026 | A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected… |
| CVE-2025-54948 | Crítica (9.8) | 22% | ⚠ Explotación activa | 5 ago 2025 | A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious code and execute commands on affected installations. |
| CVE-2023-41179 | Alta (7.2) | 4.3% | ⚠ Explotación activa | 19 sept 2023 | A vulnerability in the 3rd party AV uninstaller module contained in Trend Micro Apex One (on-prem and SaaS), Worry-Free Business Security and Worry-Free Business Security Services could allow an attacker to manipulate… |
| CVE-2022-40139 | Alta (7.2) | 3.3% | ⚠ Explotación activa | 19 sept 2022 | Improper validation of some components used by the rollback mechanism in Trend Micro Apex One and Trend Micro Apex One as a Service clients could allow a Apex One server administrator to instruct affected clients to… |
| CVE-2022-26871 | Crítica (9.8) | 19% | ⚠ Explotación activa | 29 mar 2022 | An arbitrary file upload vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to upload an arbitrary file which could lead to remote code execution. |
| CVE-2021-36742 | Alta (7.8) | 1.5% | ⚠ Explotación activa | 29 jul 2021 | A improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG and Worry-Free Business Security 10.0 SP1 allows a local attacker to escalate privileges on affected installations.… |
| CVE-2021-36741 | Alta (8.8) | 5.0% | ⚠ Explotación activa | 29 jul 2021 | An improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG, and Worry-Free Business Security 10.0 SP1 allows a remote attached to upload arbitrary files on affected… |
| CVE-2020-24557 | Alta (7.8) | 2.7% | ⚠ Explotación activa | 1 sept 2020 | A vulnerability in Trend Micro Apex One and Worry-Free Business Security 10.0 SP1 on Microsoft Windows may allow an attacker to manipulate a particular product folder to disable the security temporarily, abuse a… |
| CVE-2020-8468 | Alta (8.8) | 6.2% | ⚠ Explotación activa | 18 mar 2020 | Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) agents are affected by a content validation escape vulnerability which could allow an attacker to manipulate certain agent… |
| CVE-2020-8467 | Alta (8.8) | 11% | ⚠ Explotación activa | 18 mar 2020 | A migration tool component of Trend Micro Apex One (2019) and OfficeScan XG contains a vulnerability which could allow remote attackers to execute arbitrary code on affected installations (RCE). An attempted attack… |
| CVE-2020-8599 | Crítica (9.8) | 12% | ⚠ Explotación activa | 18 mar 2020 | Trend Micro Apex One (2019) and OfficeScan XG server contain a vulnerable EXE file that could allow a remote attacker to write arbitrary data to an arbitrary path on affected installations and bypass ROOT login.… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-45208 | Alta (7.8) | 0.13% | — | 21 may 2026 | A time-of-check time-of-use vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute… |
| CVE-2026-45207 | Alta (7.8) | 0.10% | — | 21 may 2026 | An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affected installations. This is similar to CVE-2026-45206 but exists in a different process protection… |
| CVE-2026-45206 | Alta (7.8) | 0.10% | — | 21 may 2026 | An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affected installations. This is similar to CVE-2026-45207 but exists in a different process protection… |
| CVE-2026-34930 | Alta (7.8) | 0.10% | — | 21 may 2026 | An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affected installations. This is similar to CVE-2026-34927 but exists in a different process protection… |
| CVE-2026-34929 | Alta (7.8) | 0.10% | — | 21 may 2026 | An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affected installations. This is similar to CVE-2026-34927 but exists in a different inter-process… |
| CVE-2026-34928 | Alta (7.8) | 0.10% | — | 21 may 2026 | An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affected installations. This is similar to CVE-2026-34927 but exists in a different named pipe… |
| CVE-2026-34927 | Alta (7.8) | 0.10% | — | 21 may 2026 | An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute… |
| CVE-2026-34926 | Media (6.7) | 0.54% | ⚠ Explotación activa | 21 may 2026 | A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected… |
| CVE-2025-71217 | Alta (7.8) | 0.29% | — | 21 may 2026 | An origin validation error vulnerability in the Trend Micro Apex One (mac) agent self-protection mechanism could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must… |
| CVE-2025-71216 | Alta (7.8) | 0.32% | — | 21 may 2026 | A time-of-check time-of-use vulnerability in the Trend Micro Apex One (mac) agent cache mechanism could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain… |
| CVE-2025-71215 | Alta (7) | 0.30% | — | 21 may 2026 | A time-of-check time-of-use vulnerability in the Trend Micro Apex One (mac) agent iCore service signature verification could allow a local attacker to escalate privileges on affected installations. Please note: an… |
| CVE-2025-71214 | Alta (7.8) | 0.36% | — | 21 may 2026 | An origin validation error vulnerability in the Trend Micro Apex One (mac) agent iCore service could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain… |
| CVE-2025-71213 | Alta (7.8) | 0.34% | — | 21 may 2026 | An origin validation error vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute… |
| CVE-2025-71212 | Alta (7.8) | 0.54% | — | 21 may 2026 | A link following vulnerability in the Trend Micro Apex One scan engine could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute… |
| CVE-2025-71211 | Crítica (9.8) | 3.8% | — | 21 may 2026 | A vulnerability in the Trend Micro Apex One management console could allow a remote attacker to upload malicious code and execute commands on affected installations. This vulnerability is similar in scope to… |
| CVE-2025-71210 | Crítica (9.8) | 3.8% | — | 21 may 2026 | A vulnerability in the Trend Micro Apex One management console could allow a remote attacker to upload malicious code and execute commands on affected installations. Please note: although this vulnerability carries a… |
| CVE-2025-54987 | Crítica (9.8) | 18% | — | 5 ago 2025 | A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious code and execute commands on affected installations. This vulnerability is… |
| CVE-2025-54948 | Crítica (9.8) | 22% | ⚠ Explotación activa | 5 ago 2025 | A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious code and execute commands on affected installations. |
| CVE-2025-49158 | Alta (7.8) | 0.16% | — | 17 jun 2025 | An uncontrolled search path vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalation privileges on affected installations. Please note: an attacker must first obtain the… |
| CVE-2025-49157 | Alta (7.8) | 0.19% | — | 17 jun 2025 | A link following vulnerability in the Trend Micro Apex One Damage Cleanup Engine could allow a local attacker to escalation privileges on affected installations. Please note: an attacker must first obtain the ability to… |
| CVE-2025-49156 | Alta (7.8) | 0.15% | — | 17 jun 2025 | A link following vulnerability in the Trend Micro Apex One scan engine could allow a local attacker to escalation privileges on affected installations. Please note: an attacker must first obtain the ability to execute… |
| CVE-2025-49155 | Alta (8.8) | 0.92% | — | 17 jun 2025 | An uncontrolled search path vulnerability in the Trend Micro Apex One Data Loss Prevention module could allow an attacker to inject malicious code leading to arbitrary code execution on affected installations. |
| CVE-2025-49154 | Alta (7.8) | 0.12% | — | 17 jun 2025 | An insecure access control vulnerability in Trend Micro Apex One and Trend Micro Worry-Free Business Security could allow a local attacker to overwrite key memory-mapped files which could then have severe consequences… |
| CVE-2024-58105 | Alta (7.8) | 0.16% | — | 25 mar 2025 | A vulnerability in the Trend Micro Apex One Security Agent Plug-in User Interface Manager could allow a local attacker to bypass existing security and execute arbitrary code on affected installations. This CVE address… |
| CVE-2024-58104 | Alta (7.8) | 0.16% | — | 25 mar 2025 | A vulnerability in the Trend Micro Apex One Security Agent Plug-in User Interface Manager could allow a local attacker to bypass existing security and execute arbitrary code on affected installations. Please note: an… |
| CVE-2024-55917 | Alta (7.8) | 0.26% | — | 31 dic 2024 | An origin validation error vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute… |
| CVE-2024-55632 | Alta (7.8) | 0.33% | — | 31 dic 2024 | A security agent link following vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute… |
| CVE-2024-55631 | Alta (7.8) | 0.33% | — | 31 dic 2024 | An engine link following vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute… |
| CVE-2024-52050 | Alta (7.8) | 0.47% | — | 31 dic 2024 | A LogServer arbitrary file creation vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute… |
| CVE-2024-52049 | Alta (7.8) | 0.33% | — | 31 dic 2024 | A LogServer link following vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. This vulnerability is similar to, but not identical to CVE-2024-52048.… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de Trendmicro
Officescan · 71Worry-free Business Security · 58Apex Central · 35Interscan WEB Security Virtual Appliance · 29Worry-free Business Security Services · 25Control Manager · 22Mobile Security · 21Email Encryption Gateway · 19Serverprotect · 18Internet Security · 17Password Manager · 15Deep Security Agent · 15