Apex One
Vendor:
First CVE: Apr 5, 2019 · Active for 7 years
180
Total CVEs
More Total CVEs than 100% of tracked products
22.5
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 50% of tracked products
6.1%
KEV Rate
Higher KEV Rate than 98% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Apex One over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 5, 2019
7 years ago
Most Recent CVE
May 21, 2026
68 days ago
CVE Severity & Scoring
Apex One180 CVEs
26%
67%
All CVEs352,785 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local125 (69.4%)
Network55 (30.6%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low171 (95.0%)
High9 (5.0%)
Unknown0 (0.0%)
User Interaction
None174 (96.7%)
Unknown0 (0.0%)
Required6 (3.3%)
Privileges Required
Low126 (70.0%)
High8 (4.4%)
None46 (25.6%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (180 CVEs).
180 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-54948CRITICAL A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious code and execute commands on affected in | Aug 5, 2025 | 9.8 | 83 | YES | NO |
CVE-2026-34926MEDIUM A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code | May 21, 2026 | 6.7 | 80 | YES | NO |
CVE-2022-26871CRITICAL An arbitrary file upload vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to upload an arbitrary file which could lead to remote code execut | Mar 29, 2022 | 9.8 | 78 | YES | NO |
CVE-2020-8599CRITICAL Trend Micro Apex One (2019) and OfficeScan XG server contain a vulnerable EXE file that could allow a remote attacker to write arbitrary data to an arbitrary path on affected insta | Mar 18, 2020 | 9.8 | 74 | YES | NO |
CVE-2020-8467HIGH A migration tool component of Trend Micro Apex One (2019) and OfficeScan XG contains a vulnerability which could allow remote attackers to execute arbitrary code on affected instal | Mar 18, 2020 | 8.8 | 71 | YES | NO |
CVE-2020-8468HIGH Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) agents are affected by a content validation escape vulnerability which could allow an a | Mar 18, 2020 | 8.8 | 68 | YES | NO |
CVE-2021-36741HIGH An improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG, and Worry-Free Business Security 10.0 SP1 allows a remote attached to uplo | Jul 29, 2021 | 8.8 | 67 | YES | NO |
CVE-2023-41179HIGH A vulnerability in the 3rd party AV uninstaller module contained in Trend Micro Apex One (on-prem and SaaS), Worry-Free Business Security and Worry-Free Business Security Services | Sep 19, 2023 | 7.2 | 64 | YES | NO |
CVE-2020-24557HIGH A vulnerability in Trend Micro Apex One and Worry-Free Business Security 10.0 SP1 on Microsoft Windows may allow an attacker to manipulate a particular product folder to disable th | Sep 1, 2020 | 7.8 | 64 | YES | NO |
CVE-2022-40139HIGH Improper validation of some components used by the rollback mechanism in Trend Micro Apex One and Trend Micro Apex One as a Service clients could allow a Apex One server administra | Sep 19, 2022 | 7.2 | 63 | YES | NO |
Exploit Exposure
Signals from CVEs in this product scope (180 CVEs).
CISA KEV
11 CVEs
6.1% of CVEs· 98th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (180 CVEs).
Media Mentions
Signals from CVEs in this product scope (180 CVEs).
Top CNAs Publishing CVEs For Apex One
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| saas | 12 | 6.4 | 1.2% | 0 | 0 |
| 2019 | 140 | 7.2 | 1.5% | 9 | 0 |