Vendor
Trend Micro vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 22 vulnerabilities in Trend Micro: 0 in the last 7 days and 0 in the last 90 days, 9 of them critical and 7 exploited in the wild. The most recent, CVE-2026-45208, was published on 21 May 2026. 7 technologies have a page of their own.
- Last 7 days
- 0
- Last 90 days
- 0
- Critical, all time
- 9
- Exploited in the wild
- 7
About Trend Micro
A multinational cyber security software company.
Trend Micro technologies
- Trend Micro Apex One Agent6
- Trend Micro Apex One as a Service Agent6
- Trend Micro OfficeScan5
- Trend Micro Vision One Endpoint Security Agent5
- Trend Micro Vision-One-Endpoint-Standard-Endpoint-Protection4
- Trend Micro Apex One (Mac) Agent3
- Trend Micro Vision One Endpoint Security - Standard Endpoint Protection Agent3
Latest Trend Micro vulnerabilities
- CVE-2026-45208: Trend Micro Apex One and Vision One SEP TOCTOU privilege escalationhighCVSS 7.8
- CVE-2026-45207: Trend Micro Apex One and Vision One privilege escalation in Security AgenthighCVSS 7.8
- CVE-2026-45206: Trend Micro Apex One and Vision One SEP privilege escalation in agenthighCVSS 7.8
- CVE-2026-34930: Trend Micro Apex One and Vision One SEP agent privilege escalationhighCVSS 7.8
- CVE-2026-34929: Trend Micro Apex One origin validation privilege escalation in IPChighCVSS 7.8
- CVE-2026-34928: Trend Micro Apex One origin validation privilege escalation in agent named pipehighCVSS 7.8
- CVE-2026-34927: Trend Micro Apex One and Vision One SEP origin validation privilege escalationhighCVSS 7.8
- CVE-2026-34926: Trend Micro Apex One directory traversal in on-premise servercriticalexploited in the wildCVSS 6.7
- CVE-2025-71217: Trend Micro Apex One (mac) privilege escalation in TmSelfProtectinfoCVSS 7.8
- CVE-2025-71216: Trend Micro Apex One (mac) TOCTOU privilege escalation in agent cacheinfoCVSS 7.8
- CVE-2025-71215: Trend Micro Apex One privilege escalation in iCore serviceinfoCVSS 7.8
- CVE-2025-71214: Trend Micro Apex One privilege escalation in iCore serviceinfoCVSS 7.8
- CVE-2025-71213: Trend Micro Apex One privilege escalation in NT Listener servicehighCVSS 7.8
- CVE-2025-71212: Trend Micro Apex One privilege escalation in Scan EnginehighCVSS 7.8
- CVE-2025-71211: Trend Micro Apex One directory traversal in management consolecriticalCVSS 9.8
- CVE-2025-71210: Trend Micro Apex One directory traversal in management consolecriticalCVSS 9.8
- CVE-2025-34291: Langflow CORS misconfiguration enables Account Takeover and RCEcriticalexploited in the wildCVSS 8.8EPSS 92.8%
- CVE-2019-18187: Trend Micro OfficeScan Directory Traversal Vulnerabilitycriticalexploited in the wildCVSS 8.8
- CVE-2020-8468: Trend Micro Multiple Products Content Validation Escape Vulnerabilitycriticalexploited in the wildCVSS 8.8
- CVE-2020-8599: Trend Micro Apex One and OfficeScan Authentication Bypass Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2020-8467: Trend Micro Apex One and OfficeScan Remote Code Execution Vulnerabilitycriticalexploited in the wildCVSS 8.8
- CVE-2020-24557: Trend Micro Multiple Products Improper Access Control Vulnerabilitycriticalexploited in the wildCVSS 7.8
Most severe Trend Micro vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2020-8599: Trend Micro Apex One and OfficeScan Authentication Bypass Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2025-34291: Langflow CORS misconfiguration enables Account Takeover and RCEcriticalexploited in the wildCVSS 8.8EPSS 92.8%
- CVE-2019-18187: Trend Micro OfficeScan Directory Traversal Vulnerabilitycriticalexploited in the wildCVSS 8.8
- CVE-2020-8467: Trend Micro Apex One and OfficeScan Remote Code Execution Vulnerabilitycriticalexploited in the wildCVSS 8.8
- CVE-2020-8468: Trend Micro Multiple Products Content Validation Escape Vulnerabilitycriticalexploited in the wildCVSS 8.8
- CVE-2020-24557: Trend Micro Multiple Products Improper Access Control Vulnerabilitycriticalexploited in the wildCVSS 7.8
- CVE-2026-34926: Trend Micro Apex One directory traversal in on-premise servercriticalexploited in the wildCVSS 6.7
- CVE-2025-71211: Trend Micro Apex One directory traversal in management consolecriticalCVSS 9.8
- CVE-2025-71210: Trend Micro Apex One directory traversal in management consolecriticalCVSS 9.8
- CVE-2026-45208: Trend Micro Apex One and Vision One SEP TOCTOU privilege escalationhighCVSS 7.8
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/trend-micro.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Trend Micro vulnerabilities", https://junglewise.ai/threats/vendors/trend-micro, 26 September 2026.