Skip to content
COOEY

EXPOSURES › CVE-2022-26871

CVE-2022-26871

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-03-31 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2022-26871 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 rceexploited-in-wildunpatched

Trend Micro Apex Central allowed remote code execution via an arbitrary file upload flaw.

An arbitrary file upload vulnerability in Trend Micro Apex Central enabled remote code execution, allowing attackers to upload and execute malicious files on the system. DIB organizations must ensure Apex Central is patched and monitored for exploitation, as this flaw was actively exploited in the wild. The failure highlights the risk of unpatched vulnerabilities in security management tools, which can compromise the very systems meant to protect the network.

Shame score — A critical RCE flaw in a security management product was actively exploited in the wild, demonstrating severe negligence in patching and vulnerability management.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

An arbitrary file upload vulnerability in Trend Micro Apex Central could allow for remote code execution.

AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
Trend Micro Cloud One for Government
Trend Micro Inc.
In Process
Trend Micro Vision One for Government
Trend Micro Inc.
In Process