EXPOSURES › CVE-2022-26871
CVE-2022-26871
HIGH ⌖ ON CISA KEV · EXPLOITEDTrend Micro Apex Central allowed remote code execution via an arbitrary file upload flaw.
An arbitrary file upload vulnerability in Trend Micro Apex Central enabled remote code execution, allowing attackers to upload and execute malicious files on the system. DIB organizations must ensure Apex Central is patched and monitored for exploitation, as this flaw was actively exploited in the wild. The failure highlights the risk of unpatched vulnerabilities in security management tools, which can compromise the very systems meant to protect the network.
Shame score — A critical RCE flaw in a security management product was actively exploited in the wild, demonstrating severe negligence in patching and vulnerability management.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
An arbitrary file upload vulnerability in Trend Micro Apex Central could allow for remote code execution.
| PRODUCT | STATUS |
|---|---|
| Trend Micro Cloud One for Government Trend Micro Inc. |
In Process |
| Trend Micro Vision One for Government Trend Micro Inc. |
In Process |