Trend Micro: CISA KEV History
Every Trend Micro vulnerability in the CISA Known Exploited Vulnerabilities catalog: confirmed in-the-wild exploitation, addition timeline, and ransomware linkage. Rebuilt automatically on every site deploy.
Snapshot: 2026-09-08 · Source: CISA KEV Catalog · Full KEV dashboard
KEV entries
12
Added, last 12 months
1
Ransomware-linked
0
Latest addition
2026-05-21
Trend Micro KEV additions per month, last 24 months
Most-listed products: Apex One, Apex One and OfficeScan, Apex One, Apex One as a Service, and Worry-Free Business Security, Apex One and Worry-Free Business Security, Apex One and Apex One as a Service.
Latest 12 of 12 Trend Micro KEV entries
| CVE | Vulnerability | Added | Ransomware |
|---|---|---|---|
| CVE-2026-34926 | Trend Micro Apex One (On-Premise) Directory Traversal Vulnerability | 2026-05-21 | No |
| CVE-2025-54948 | Trend Micro Apex One OS Command Injection Vulnerability | 2025-08-18 | No |
| CVE-2023-41179 | Trend Micro Apex One and Worry-Free Business Security Remote Code Execution Vulnerability | 2023-09-21 | No |
| CVE-2022-40139 | Trend Micro Apex One and Apex One as a Service Improper Validation Vulnerability | 2022-09-15 | No |
| CVE-2022-26871 | Trend Micro Apex Central Arbitrary File Upload Vulnerability | 2022-03-31 | No |
| CVE-2019-18187 | Trend Micro OfficeScan Directory Traversal Vulnerability | 2021-11-03 | No |
| CVE-2020-8467 | Trend Micro Apex One and OfficeScan Remote Code Execution Vulnerability | 2021-11-03 | No |
| CVE-2020-8468 | Trend Micro Multiple Products Content Validation Escape Vulnerability | 2021-11-03 | No |
| CVE-2020-24557 | Trend Micro Multiple Products Improper Access Control Vulnerability | 2021-11-03 | No |
| CVE-2020-8599 | Trend Micro Apex One and OfficeScan Authentication Bypass Vulnerability | 2021-11-03 | No |
| CVE-2021-36742 | Trend Micro Multiple Products Improper Input Validation Vulnerability | 2021-11-03 | No |
| CVE-2021-36741 | Trend Micro Multiple Products Improper Input Validation Vulnerability | 2021-11-03 | No |
CVE links go to our explainer when one exists, otherwise to the NVD record.
Data: official CISA KEV catalog, fetched at build time. Figures may be reused with attribution to East Bay Cyber and CISA. See also the KEV Velocity Dashboard and all tracked vendors.