EXPOSURES › CVE-2021-36741
CVE-2021-36741
HIGH ⌖ ON CISA KEV · EXPLOITEDTrend Micro Apex One and Worry-Free Business Security suffered an improper input validation flaw allowing remote attackers to upload arbitrary files.
The improper input validation vulnerability in Trend Micro's Apex One and Worry-Free Business Security products allowed remote attackers to upload files, potentially leading to system compromise. DIB organizations must ensure these products are patched immediately, as the flaw was actively exploited in the wild and represents a significant compliance risk under CMMC/NIST 800-171. Organizations should verify their security posture and update all Trend Micro endpoints to prevent exploitation.
Shame score — The vulnerability was actively exploited in the wild (KEV list) and allowed remote attackers to upload files, indicating a severe, avoidable security failure that could lead to system compromise.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Trend Micro Apex One, Apex One as a Service, and Worry-Free Business Security contain an improper input validation vulnerability that allows a remote attacker to upload files.
"Trend Micro Apex One, Apex One as a Service, and Worry-Free Business Security contain an improper input validation vulnerability that allows a remote attacker to upload files."
| PRODUCT | STATUS |
|---|---|
| Trend Micro Cloud One for Government Trend Micro Inc. |
In Process |
| Trend Micro Vision One for Government Trend Micro Inc. |
In Process |