Exploited CVEs / By vendor / Trend Micro

Trend Micro vulnerabilities actively exploited

12 Trend Micro CVEs on the CISA Known Exploited Vulnerabilities catalog, newest first. Refreshed daily.

Every CVE below is confirmed exploited in the wild, not just theoretically severe. The newest addition is CVE-2026-34926 (Apex One, added 2026-05-21). New CISA KEV entries appear here the day they are cataloged; the freshest across all vendors are on exploited this week.

12 exploited CVEs
Senserva AI Opinion and rich prompt for Trend Micro exploited CVEs

Copy this prompt into Claude, ChatGPT, or Copilot. The facts are included, sourced from this page.

All Trend Micro entries

CVEProductAdded to KEVSignals
CVE-2026-34926Apex One2026-05-21CVSS 6.7, EPSS 13%
CVE-2025-54948Apex One2025-08-18CVSS 9.8, EPSS 21%
CVE-2023-41179Apex One and Worry-Free Business Security2023-09-21CVSS 7.2, EPSS 5%
CVE-2022-40139Apex One and Apex One as a Service2022-09-15CVSS 7.2, EPSS 3%
CVE-2022-26871Apex Central2022-03-31CVSS 9.8, EPSS 20%
CVE-2019-18187OfficeScan2021-11-03CVSS 7.5, EPSS 25%
CVE-2020-24557Apex One, OfficeScan, and Worry-Free Business Security2021-11-03CVSS 7.8, EPSS 3%
CVE-2020-8467Apex One and OfficeScan2021-11-03CVSS 8.8, EPSS 11%
CVE-2020-8468Apex One, OfficeScan and Worry-Free Business Security Agents2021-11-03CVSS 8.8, EPSS 6%
CVE-2020-8599Apex One and OfficeScan2021-11-03CVSS 9.8, EPSS 12%
CVE-2021-36741Apex One, Apex One as a Service, and Worry-Free Business Security2021-11-03CVSS 8.8, EPSS 5%
CVE-2021-36742Apex One, Apex One as a Service, and Worry-Free Business Security2021-11-03CVSS 7.8, EPSS 1%

Common questions about exploited Trend Micro CVEs

Which Trend Micro vulnerabilities are actively exploited?

As of August 2026, 12 Trend Micro CVEs are on the CISA Known Exploited Vulnerabilities catalog, meaning exploitation in the wild is confirmed.

What is the newest exploited Trend Micro CVE?

CVE-2026-34926, affecting Apex One, added to the CISA KEV catalog on 2026-05-21. This page refreshes daily, so the newest entry is always first in the table.

How urgent are these Trend Micro CVEs?

KEV listing is the strongest fix-first signal there is: it means confirmed exploitation, not a prediction. Patch these ahead of higher-CVSS issues that nobody is exploiting. Check the vendor advisory (linked below) for fixed versions and workarounds.

Can I ask my own AI about exploited Trend Micro CVEs?

Yes. This page includes a free copy-paste AI prompt carrying the newest Trend Micro KEV entries, with CVSS, EPSS, and ransomware context, into Claude, ChatGPT, or Copilot. The data is refreshed twice a day (5 AM and 3 PM US Central).

All vendors, searchable with due dates and CSV export: the exploited-CVE tracker. Every vendor with a page: exploited by vendor.

Most searched on Senserva right now

New to a term on this page? CVE, KB, KEV, CVSS, and EPSS are each explained once, on the Senserva security lexicon. Reference: Microsoft CVE and vulnerability management and the Microsoft patching guide.
Provided as is, without warranty; verify against the vendor advisory before acting. Data notice and terms.