« Volver al listado

Trendmicro

Trendmicro Apex ONE: vulnerabilidades y CVE

Trendmicro Apex ONE tiene 180 vulnerabilidades publicadas, 16 de ellas en los últimos 12 meses. 13 son críticas y 11 figuran en el catálogo de explotación activa de CISA.

CVE180
Últimos 12 meses16
Críticas13
Explotadas activamente11

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-34926Media (6.7)0.54%⚠ Explotación activa21 may 2026
A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected…
CVE-2025-54948Crítica (9.8)22%⚠ Explotación activa5 ago 2025
A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious code and execute commands on affected installations.
CVE-2023-41179Alta (7.2)4.3%⚠ Explotación activa19 sept 2023
A vulnerability in the 3rd party AV uninstaller module contained in Trend Micro Apex One (on-prem and SaaS), Worry-Free Business Security and Worry-Free Business Security Services could allow an attacker to manipulate…
CVE-2022-40139Alta (7.2)3.3%⚠ Explotación activa19 sept 2022
Improper validation of some components used by the rollback mechanism in Trend Micro Apex One and Trend Micro Apex One as a Service clients could allow a Apex One server administrator to instruct affected clients to…
CVE-2022-26871Crítica (9.8)19%⚠ Explotación activa29 mar 2022
An arbitrary file upload vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to upload an arbitrary file which could lead to remote code execution.
CVE-2021-36742Alta (7.8)1.5%⚠ Explotación activa29 jul 2021
A improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG and Worry-Free Business Security 10.0 SP1 allows a local attacker to escalate privileges on affected installations.…
CVE-2021-36741Alta (8.8)5.0%⚠ Explotación activa29 jul 2021
An improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG, and Worry-Free Business Security 10.0 SP1 allows a remote attached to upload arbitrary files on affected…
CVE-2020-24557Alta (7.8)2.7%⚠ Explotación activa1 sept 2020
A vulnerability in Trend Micro Apex One and Worry-Free Business Security 10.0 SP1 on Microsoft Windows may allow an attacker to manipulate a particular product folder to disable the security temporarily, abuse a…
CVE-2020-8468Alta (8.8)6.2%⚠ Explotación activa18 mar 2020
Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) agents are affected by a content validation escape vulnerability which could allow an attacker to manipulate certain agent…
CVE-2020-8467Alta (8.8)11%⚠ Explotación activa18 mar 2020
A migration tool component of Trend Micro Apex One (2019) and OfficeScan XG contains a vulnerability which could allow remote attackers to execute arbitrary code on affected installations (RCE). An attempted attack…
CVE-2020-8599Crítica (9.8)12%⚠ Explotación activa18 mar 2020
Trend Micro Apex One (2019) and OfficeScan XG server contain a vulnerable EXE file that could allow a remote attacker to write arbitrary data to an arbitrary path on affected installations and bypass ROOT login.…

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-45208Alta (7.8)0.13%—21 may 2026
A time-of-check time-of-use vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute…
CVE-2026-45207Alta (7.8)0.10%—21 may 2026
An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affected installations. This is similar to CVE-2026-45206 but exists in a different process protection…
CVE-2026-45206Alta (7.8)0.10%—21 may 2026
An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affected installations. This is similar to CVE-2026-45207 but exists in a different process protection…
CVE-2026-34930Alta (7.8)0.10%—21 may 2026
An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affected installations. This is similar to CVE-2026-34927 but exists in a different process protection…
CVE-2026-34929Alta (7.8)0.10%—21 may 2026
An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affected installations. This is similar to CVE-2026-34927 but exists in a different inter-process…
CVE-2026-34928Alta (7.8)0.10%—21 may 2026
An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affected installations. This is similar to CVE-2026-34927 but exists in a different named pipe…
CVE-2026-34927Alta (7.8)0.10%—21 may 2026
An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute…
CVE-2026-34926Media (6.7)0.54%⚠ Explotación activa21 may 2026
A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected…
CVE-2025-71217Alta (7.8)0.29%—21 may 2026
An origin validation error vulnerability in the Trend Micro Apex One (mac) agent self-protection mechanism could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must…
CVE-2025-71216Alta (7.8)0.32%—21 may 2026
A time-of-check time-of-use vulnerability in the Trend Micro Apex One (mac) agent cache mechanism could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain…
CVE-2025-71215Alta (7)0.30%—21 may 2026
A time-of-check time-of-use vulnerability in the Trend Micro Apex One (mac) agent iCore service signature verification could allow a local attacker to escalate privileges on affected installations. Please note: an…
CVE-2025-71214Alta (7.8)0.36%—21 may 2026
An origin validation error vulnerability in the Trend Micro Apex One (mac) agent iCore service could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain…
CVE-2025-71213Alta (7.8)0.34%—21 may 2026
An origin validation error vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute…
CVE-2025-71212Alta (7.8)0.54%—21 may 2026
A link following vulnerability in the Trend Micro Apex One scan engine could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute…
CVE-2025-71211Crítica (9.8)3.8%—21 may 2026
A vulnerability in the Trend Micro Apex One management console could allow a remote attacker to upload malicious code and execute commands on affected installations. This vulnerability is similar in scope to…
CVE-2025-71210Crítica (9.8)3.8%—21 may 2026
A vulnerability in the Trend Micro Apex One management console could allow a remote attacker to upload malicious code and execute commands on affected installations. Please note: although this vulnerability carries a…
CVE-2025-54987Crítica (9.8)18%—5 ago 2025
A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious code and execute commands on affected installations. This vulnerability is…
CVE-2025-54948Crítica (9.8)22%⚠ Explotación activa5 ago 2025
A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious code and execute commands on affected installations.
CVE-2025-49158Alta (7.8)0.16%—17 jun 2025
An uncontrolled search path vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalation privileges on affected installations. Please note: an attacker must first obtain the…
CVE-2025-49157Alta (7.8)0.19%—17 jun 2025
A link following vulnerability in the Trend Micro Apex One Damage Cleanup Engine could allow a local attacker to escalation privileges on affected installations. Please note: an attacker must first obtain the ability to…
CVE-2025-49156Alta (7.8)0.15%—17 jun 2025
A link following vulnerability in the Trend Micro Apex One scan engine could allow a local attacker to escalation privileges on affected installations. Please note: an attacker must first obtain the ability to execute…
CVE-2025-49155Alta (8.8)0.92%—17 jun 2025
An uncontrolled search path vulnerability in the Trend Micro Apex One Data Loss Prevention module could allow an attacker to inject malicious code leading to arbitrary code execution on affected installations.
CVE-2025-49154Alta (7.8)0.12%—17 jun 2025
An insecure access control vulnerability in Trend Micro Apex One and Trend Micro Worry-Free Business Security could allow a local attacker to overwrite key memory-mapped files which could then have severe consequences…
CVE-2024-58105Alta (7.8)0.16%—25 mar 2025
A vulnerability in the Trend Micro Apex One Security Agent Plug-in User Interface Manager could allow a local attacker to bypass existing security and execute arbitrary code on affected installations. This CVE address…
CVE-2024-58104Alta (7.8)0.16%—25 mar 2025
A vulnerability in the Trend Micro Apex One Security Agent Plug-in User Interface Manager could allow a local attacker to bypass existing security and execute arbitrary code on affected installations. Please note: an…
CVE-2024-55917Alta (7.8)0.26%—31 dic 2024
An origin validation error vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute…
CVE-2024-55632Alta (7.8)0.33%—31 dic 2024
A security agent link following vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute…
CVE-2024-55631Alta (7.8)0.33%—31 dic 2024
An engine link following vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute…
CVE-2024-52050Alta (7.8)0.47%—31 dic 2024
A LogServer arbitrary file creation vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute…
CVE-2024-52049Alta (7.8)0.33%—31 dic 2024
A LogServer link following vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations. This vulnerability is similar to, but not identical to CVE-2024-52048.…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1068 Exploitation for Privilege Escalation16
  2. T1059 Command and Scripting Interpreter7
  3. T1548 Abuse Elevation Control Mechanism7
  4. T1190 Exploit Public-Facing Application5
  5. T1210 Exploitation of Remote Services5
  6. T1059.003 Windows Command Shell1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Trendmicro