Trend Micro, Inc.
First CVE: Aug 1, 2017Active for: 9 years
506
CVEs Published
More CVEs Published than 86% of tracked CNAs
50.6
Avg CVEs / Year
More Avg CVEs / Year than 84% of tracked CNAs
7.5
Avg CVSS Score
Higher Avg CVSS Score than 66% of tracked CNAs
2.4%
In CISA KEV
Higher KEV Rate than 92% of tracked CNAs
Self-Reporting Analysis
Of all the CVEs published by Trend Micro, Inc. as a CNA, 100.0% affect products that Trend Micro, Inc. develops as a vendor.
100.0%
Self-reported: 506Third-party: 0
Of all the CVEs published that affect products developed by Trend Micro, Inc., 88.0% are self-published by Trend Micro, Inc. as a CNA.
88.0%
12.0%
Self-published: 506Published by other CNAs: 69
Trends Over Time
The number and severity of CVEs published by Trend Micro, Inc. over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 1, 2017
8 years ago
Most Recent CVE
May 21, 2026
64 days ago
Top CVEs
All CVEs published by Trend Micro, Inc. as a CNA, regardless of affected vendor or product.
506 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-8605HIGH A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to execute arbitrary code on affected installations. Authentication is requir | May 27, 2020 | 8.8 | 88 | NO | YES |
CVE-2025-54948CRITICAL A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious code and execute commands on affected in | Aug 5, 2025 | 9.8 | 83 | YES | NO |
CVE-2020-8604HIGH A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to disclose sensitive informatoin on affected installations. | May 27, 2020 | 7.5 | 82 | NO | YES |
CVE-2026-34926MEDIUM A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code | May 21, 2026 | 6.7 | 80 | YES | NO |
CVE-2020-8606CRITICAL A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to bypass authentication on affected installations of Trend Micro InterScan W | May 27, 2020 | 9.8 | 80 | NO | YES |
CVE-2022-26871CRITICAL An arbitrary file upload vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to upload an arbitrary file which could lead to remote code execut | Mar 29, 2022 | 9.8 | 78 | YES | NO |
CVE-2017-11394CRITICAL Proxy command injection vulnerability in Trend Micro OfficeScan 11 and XG (12) allows remote attackers to execute arbitrary code on vulnerable installations. The specific flaw can | Aug 3, 2017 | 9.8 | 78 | NO | YES |
CVE-2019-18187HIGH Trend Micro OfficeScan versions 11.0 and XG (12.0) could be exploited by an attacker utilizing a directory traversal vulnerability to extract files from an arbitrary zip file to a | Oct 28, 2019 | 7.5 | 75 | YES | NO |
CVE-2020-8599CRITICAL Trend Micro Apex One (2019) and OfficeScan XG server contain a vulnerable EXE file that could allow a remote attacker to write arbitrary data to an arbitrary path on affected insta | Mar 18, 2020 | 9.8 | 74 | YES | NO |
CVE-2017-11391HIGH Proxy command injection vulnerability in Trend Micro InterScan Messaging Virtual Appliance 9.0 and 9.1 allows remote attackers to execute arbitrary code on vulnerable installations | Aug 3, 2017 | 8.8 | 72 | NO | YES |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA506 CVEs
25%
61%
12%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local253 (50.0%)
Network250 (49.4%)
Unknown0 (0.0%)
Physical2 (0.4%)
Adjacent Network1 (0.2%)
Attack Complexity
Low472 (93.3%)
High34 (6.7%)
Unknown0 (0.0%)
User Interaction
None434 (85.8%)
Unknown0 (0.0%)
Required72 (14.2%)
Privileges Required
Low282 (55.7%)
High33 (6.5%)
None191 (37.7%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (506 CVEs).
CISA KEV
12 CVEs
2.4% of CVEs· 92nd percentile
Metasploit
6 CVEs
1.2% of CVEs· 88th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
28 CVEs
5.5% of CVEs· 96th percentile
Social Chatter
An overview of all social media posts that mention a CVE ID published by Trend Micro, Inc. as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Trend Micro, Inc. as a CNA — matched by CVE ID, not by organization name.