peter bassill · operator
$ cve CVE-2022-26871 JSON

CVE-2022-26871 KEV

9.8
CRITICAL · CVSS 3.1 · EPSS 19.5% (pctl 97)

Patch first

On CISA KEV — known exploited in the wild, due 2022-04-21.

Description

An arbitrary file upload vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to upload an arbitrary file which could lead to remote code execution.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS19.48% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-345
On CISA KEVyes — remediate by 2022-04-21
Public exploitnone known
Published2022-03-29
Last modified2026-06-17

CISA KEV

NameTrend Micro Apex Central Arbitrary File Upload Vulnerability
Added2022-03-31
Due2022-04-21
Vendor / productTrend Micro / Apex Central
Ransomware usenone reported

Affected (2)

VendorProduct
trendmicroapex central
trendmicroapex one

References

→ the Explorer  ·  watch your stack  ·  NVD