FAIL › dossier
Apex One and OfficeScan
PRODUCT· dossier confidence 20%
Trend Micro's Apex One and OfficeScan suffered high-severity remote code execution and authentication bypass vulnerabilities that were actively exploited in the wild, indicating a critical gap in patch management and secure component design.
PROFILE
Categoryendpoint securityWhat they doApex One and OfficeScan are endpoint security and data loss prevention solutions from Trend Micro.
Websitehttps://www.trendmicro.com ↗
SECURITY POSTURE
The security posture is compromised by high-severity remote code execution and authentication bypass vulnerabilities in the migration tool and server components that were actively exploited in the wild.
Notable failures
- CVE-2020-8467 RCE in migration tool
- CVE-2020-8599 authentication bypass
- Active exploitation of unpatched RCE
Patterns: unpatched edge-device RCEs; authentication bypasses in server components
FAILURE HISTORY · 2
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2021-11-03 | CVE-2020-8467 | high | Trend Micro Apex One and OfficeScan suffered a remote code execution vulnerability in a migration tool component that was actively exploited in the wild. |
| 2021-11-03 | CVE-2020-8599 | high | Trend Micro Apex One and OfficeScan servers suffered an authentication bypass allowing remote attackers to write data and bypass root login. |
DOSSIER SOURCES
- Microsoft Patch Tracker (August 2026): 1,028 KBs, Exploit-Ranked · senserva.com
- Vulnerability Remediation Guide: Prioritize, Fix, and Verify · barrion.io
- Vulnerability Database | SentinelOne · SentinelOne
Open questions: What specific remediation steps were taken after the 2021 vulnerabilities? · How does Trend Micro currently address similar vulnerabilities in its endpoint security portfolio?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-26 04:20:36.454127+00:00