Junglewise Threat Intelligence

CVE-2022-26871: Trend Micro Apex Central Arbitrary File Upload Vulnerability

CVE-2022-26871 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-03-31

Vendors: Trend Micro, Trend Micro.

Executive brief

An arbitrary file upload vulnerability in Trend Micro Apex Central allows an unauthenticated remote attacker to upload malicious files to the server. This flaw can be leveraged to execute arbitrary code in the context of the application.

Affected products

  • Trend Micro Apex Central 2019

Timeline

  • 2022-03-29: disclosed
  • 2022-03-31: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-03-31: advisory