Share of each bar's KEVs linked to ransomware. Thresholds track the catalog average of 20.9%, so they stay meaningful as it grows. Bars under 5 KEVs are left uncoloured — too few to rate a share.
Share of each bar's KEVs linked to ransomware. Thresholds track the catalog average of 20.9%, so they stay meaningful as it grows. Bars under 5 KEVs are left uncoloured — too few to rate a share.
| CVE | Vendor | Product | Vulnerability | CVSS | Added | Due per BOD 22-01 | Ransomware |
|---|---|---|---|---|---|---|---|
| CVE-2026-34926 | Trend Micro | Apex One | Trend Micro Apex One (On-Premise) Directory Traversal Vulnerability Trend Micro Apex One (on-premise) contains a directory traversal vulnerability that could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations. | 6.7 CNA | 2026-05-21 | 2026-06-04 | Unknown |
| CVE-2025-54948 | Trend Micro | Apex One | Trend Micro Apex One OS Command Injection Vulnerability Trend Micro Apex One Management Console (on-premise) contains an OS command injection vulnerability that could allow a pre-authenticated remote attacker to upload malicious code and execute commands on affected installations. | 9.4 CNA | 2025-08-18 | 2025-09-08 | Unknown |
| CVE-2023-41179 | Trend Micro | Apex One and Worry-Free Business Security | Trend Micro Apex One and Worry-Free Business Security Remote Code Execution Vulnerability Trend Micro Apex One and Worry-Free Business Security contain an unspecified vulnerability in the third-party anti-virus uninstaller that could allow an attacker to manipulate the module to conduct remote code execution. An attacker must first obtain administrative console access on the target system in order to exploit this vulnerability. | 7.2 CISA | 2023-09-21 | 2023-10-12 | Unknown |
| CVE-2022-40139 | Trend Micro | Apex One and Apex One as a Service | Trend Micro Apex One and Apex One as a Service Improper Validation Vulnerability Trend Micro Apex One and Apex One as a Service contain an improper validation of rollback mechanism components that could lead to remote code execution. | 7.2 CISA | 2022-09-15 | 2022-10-06 | Unknown |
| CVE-2022-26871 | Trend Micro | Apex Central | Trend Micro Apex Central Arbitrary File Upload Vulnerability An arbitrary file upload vulnerability in Trend Micro Apex Central could allow for remote code execution. | 9.8 CISA | 2022-03-31 | 2022-04-21 | Unknown |
| CVE-2021-36741 | Trend Micro | Apex One, Apex One as a Service, and Worry-Free Business Security | Trend Micro Multiple Products Improper Input Validation Vulnerability Trend Micro Apex One, Apex One as a Service, and Worry-Free Business Security contain an improper input validation vulnerability that allows a remote attacker to upload files. | 8.8 CISA | 2021-11-03 | 2021-11-17 | Unknown |
| CVE-2021-36742 | Trend Micro | Apex One, Apex One as a Service, and Worry-Free Business Security | Trend Micro Multiple Products Improper Input Validation Vulnerability Trend Micro Apex One, Apex One as a Service, and Worry-Free Business Security contain an improper input validation vulnerability that allows for privilege escalation. | 7.8 CISA | 2021-11-03 | 2021-11-17 | Unknown |
| CVE-2020-8599 | Trend Micro | Apex One and OfficeScan | Trend Micro Apex One and OfficeScan Authentication Bypass Vulnerability Trend Micro Apex One and OfficeScan server contain a vulnerable EXE file that could allow a remote attacker to write data to a path on affected installations and bypass root login. | 9.8 CISA | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2020-24557 | Trend Micro | Apex One, OfficeScan, and Worry-Free Business Security | Trend Micro Multiple Products Improper Access Control Vulnerability Trend Micro Apex One, OfficeScan, and Worry-Free Business Security on Microsoft Windows contain an improper access control vulnerability that may allow an attacker to manipulate a particular product folder to disable the security temporarily, abuse a specific Windows function, and attain privilege escalation. | 7.8 CISA | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2020-8468 | Trend Micro | Apex One, OfficeScan and Worry-Free Business Security Agents | Trend Micro Multiple Products Content Validation Escape Vulnerability Trend Micro Apex One, OfficeScan, and Worry-Free Business Security agents contain a content validation escape vulnerability that could allow an attacker to manipulate certain agent client components. | 8.8 CISA | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2020-8467 | Trend Micro | Apex One and OfficeScan | Trend Micro Apex One and OfficeScan Remote Code Execution Vulnerability Trend Micro Apex One and OfficeScan contain an unspecified vulnerability within a migration tool component that allows for remote code execution. | 8.8 CISA | 2021-11-03 | 2022-05-03 | Unknown |
| CVE-2019-18187 | Trend Micro | OfficeScan | Trend Micro OfficeScan Directory Traversal Vulnerability Trend Micro OfficeScan contains a directory traversal vulnerability by extracting files from a zip file to a specific folder on the OfficeScan server, leading to remote code execution. | 8.8 CISA | 2021-11-03 | 2022-05-03 | Unknown |