trendmicro security advisories
23 threat alerts tracking vulnerabilities and security advisories that affect trendmicro products.
Vulnios monitors trendmicro CVE feeds, vendor advisories, CISA KEV listings, and exploit-prediction data continuously. Each alert below is enriched with severity, exploitation status, affected products, and a remediation path. Use this page to scan recent trendmicro security news in one place, or click into an individual alert for full detail.
Critical Vulnerability: CVE-2025-69258 — trendmicro, microsoft — apex_central, windows
A LoadLibraryEX vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to load an attacker-controlled DLL into a key executable, leading to execution of attacker-supp
criticalCVE-2025-69258Critical Vulnerability: CVE-2016-4351 — trendmicro — email_encryption_gateway
SQL injection vulnerability in the authentication functionality in Trend Micro Email Encryption Gateway (TMEEG) 5.5 before build 1107 allows remote attackers to execute arbitrary SQL commands via unsp
criticalCVE-2016-4351Critical Vulnerability: CVE-2016-3987 — trendmicro — password_manager
The HTTP server in Trend Micro Password Manager allows remote web servers to execute arbitrary commands via the url parameter to (1) api/openUrlInDefaultBrowser or (2) api/showSB.
criticalCVE-2016-3987Critical Vulnerability: CVE-2008-2433 — trendmicro — client_server_messaging_suite, officescan
The web management console in Trend Micro OfficeScan 7.0 through 8.0, Worry-Free Business Security 5.0, and Client/Server/Messaging Suite 3.5 and 3.6 creates a random session token based only on the l
criticalCVE-2008-2433Critical Vulnerability: CVE-2017-14090 — trendmicro — scanmail
A vulnerability in Trend Micro ScanMail for Exchange 12.0 exists in which some communications to the update servers are not encrypted.
criticalCVE-2017-14090Critical Vulnerability: CVE-2017-14089 — trendmicro — officescan
An Unauthorized Memory Corruption vulnerability in Trend Micro OfficeScan 11.0 and XG may allow remote unauthenticated users who can access the OfficeScan server to target cgiShowClientAdm.exe and cau
criticalCVE-2017-14089Critical Vulnerability: CVE-2017-14078 — trendmicro — mobile_security
SQL Injection vulnerabilities in Trend Micro Mobile Security (Enterprise) versions before 9.7 Patch 3 allow remote attackers to execute arbitrary code on vulnerable installations.
criticalCVE-2017-14078Critical Vulnerability: CVE-2017-14080 — trendmicro — mobile_security
Authentication bypass vulnerability in Trend Micro Mobile Security (Enterprise) versions before 9.7 Patch 3 allows attackers to access a specific part of the console using a blank password.
criticalCVE-2017-14080Critical Vulnerability: CVE-2017-11385 — trendmicro — control_manager
SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when executing opcode 0x6b1b due to lack of proper user input validation in cmdHandlerStatusMonitor.dll. Formerly ZDI-CAN-
criticalCVE-2017-11385Critical Vulnerability: CVE-2017-11386 — trendmicro — control_manager
SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when executing opcode 0x4707 due to lack of proper user input validation in cmdHandlerNewReportScheduler.dll. Formerly ZDI
criticalCVE-2017-11386Critical Vulnerability: CVE-2017-11394 — trendmicro — officescan
Proxy command injection vulnerability in Trend Micro OfficeScan 11 and XG (12) allows remote attackers to execute arbitrary code on vulnerable installations. The specific flaw can be exploited by pars
criticalCVE-2017-11394Critical Vulnerability: CVE-2017-11384 — trendmicro — control_manager
SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when executing opcode 0x3b21 due to lack of proper user input validation in mdHandlerLicenseManager.dll. Formerly ZDI-CAN-
criticalCVE-2017-11384Critical Vulnerability: CVE-2017-11389 — trendmicro — control_manager
Directory traversal vulnerability in Trend Micro Control Manager 6.0 allows remote code execution by attackers able to drop arbitrary files in a web-facing directory. Formerly ZDI-CAN-4684.
criticalCVE-2017-11389Critical Vulnerability: CVE-2017-11393 — trendmicro — officescan
Proxy command injection vulnerability in Trend Micro OfficeScan 11 and XG (12) allows remote attackers to execute arbitrary code on vulnerable installations. The specific flaw can be exploited by pars
criticalCVE-2017-11393Critical Vulnerability: CVE-2017-11383 — trendmicro — control_manager
SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when executing opcode 0x1b07 due to lack of proper user input validation in cmdHandlerTVCSCommander.dll. Formerly ZDI-CAN-
criticalCVE-2017-11383Critical Vulnerability: CVE-2017-11381 — trendmicro — deep_discovery_director
A command injection vulnerability exists in Trend Micro Deep Discovery Director 1.1 that allows an attacker to restore accounts that can access the pre-configuration console.
criticalCVE-2017-11381Critical Vulnerability: CVE-2017-11380 — trendmicro — deep_discovery_director
Backup archives were found to be encrypted with a static password across different installations, which suggest the same password may be used in all virtual appliance instances of Trend Micro Deep Dis
criticalCVE-2017-11380Critical Vulnerability: CVE-2017-9034 — trendmicro — serverprotect
Trend Micro ServerProtect for Linux 3.0 before CP 1531 allows attackers to write to arbitrary files and consequently execute arbitrary code with root privileges by leveraging failure to validate softw
criticalCVE-2017-9034Critical Vulnerability: CVE-2016-8584 — trendmicro — threat_discovery_appliance
Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier uses predictable session values, which allows remote attackers to bypass authentication by guessing the value.
criticalCVE-2016-8584Critical Vulnerability: CVE-2016-7547 — trendmicro — threat_discovery_appliance
A command execution flaw on the Trend Micro Threat Discovery Appliance 2.6.1062r1 exists with the timezone parameter in the admin_sys_time.cgi interface.
criticalCVE-2016-7547Critical Vulnerability: CVE-2016-7552 — trendmicro — threat_discovery_appliance
On the Trend Micro Threat Discovery Appliance 2.6.1062r1, directory traversal when processing a session_id cookie allows a remote, unauthenticated attacker to delete arbitrary files as root. This can
criticalCVE-2016-7552Critical Vulnerability: CVE-2016-9269 — trendmicro — interscan_web_security_virtual_appliance
Remote Command Execution in com.trend.iwss.gui.servlet.ManagePatches in Trend Micro Interscan Web Security Virtual Appliance (IWSVA) version 6.5-SP2_Build_Linux_1707 and earlier allows authenticated,
criticalCVE-2016-9269Critical Vulnerability: CVE-2016-6269 — trendmicro — smart_protection_server
Multiple directory traversal vulnerabilities in Trend Micro Smart Protection Server 2.5 before build 2200, 2.6 before build 2106, and 3.0 before build 1330 allow remote attackers to read and delete ar
criticalCVE-2016-6269
Track trendmicro exposure across your environment
Vulnios automatically cross-references your asset inventory against new trendmicro CVEs and surfaces only what affects you. No more sifting manually — actionable findings only.
Start a free scan