← Vulnerability feed

Vulnerability record · CVE-2022-26871 · published 29 March 2022

CVE-2022-26871: Trend Micro Apex Central unauthenticated arbitrary file upload

Trendmicro · Apex Central

Trend Micro Apex Central (and Apex One) contains an arbitrary file upload flaw caused by insufficient verification of data authenticity (CWE-345). An unauthenticated remote attacker can upload an arbitrary file, which the vendor and NVD state could lead to remote code execution. Because no authentication or user interaction is required and the impact is total loss of confidentiality, integrity and availability, this is a severe pre-auth flaw in a central management component.

9.8 CVSS 3.1 Critical CISA KEV since 31 Mar 2022 EPSS 19% · top 2.7% CWE-345 · Insufficient verification of data authenticity
9.8CVSS 3.1 base score, v2 7.5
19%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
11References
17 Jun 2026Last modified by NVD

Description

An arbitrary file upload vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to upload an arbitrary file which could lead to remote code execution.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 9.8 pre-auth network-exploitable file upload leading to potential RCE, listed in CISA KEV with known exploitation and a high EPSS percentile.

What it is

Trend Micro Apex Central (and Apex One) contains an arbitrary file upload flaw caused by insufficient verification of data authenticity (CWE-345). An unauthenticated remote attacker can upload an arbitrary file, which the vendor and NVD state could lead to remote code execution. Because no authentication or user interaction is required and the impact is total loss of confidentiality, integrity and availability, this is a severe pre-auth flaw in a central management component.

Impact

An attacker gains the ability to place arbitrary files on the server and, per the description, potentially achieve remote code execution. Successful exploitation would give full control of the affected Apex Central host (CVSS 9.8, C/I/A all High).

Attack surface

Reachable over the network (AV:N) with no privileges (PR:N) and no user interaction (UI:N), per the CVSS vector. Any internet- or network-exposed Apex Central instance is a candidate target; the record does not specify the exact endpoint or port.

Exploitation

CVE-2022-26871 was added to CISA KEV on 2022-03-31 with a remediation due date of 2022-04-21, indicating known exploitation in the wild. EPSS gives a 30-day probability of 0.19633 (97.2nd percentile), and references carry Patch and Mitigation tags; KEV lists no known ransomware campaign use.

What to do

  • Apply the vendor patches referenced in the Trend Micro advisories (success.trendmicro.com solutions 000290660 and 000290678) as the first action.
  • If patching cannot be done immediately, apply the mitigations described in those same Trend Micro advisories.
  • Remove Apex Central management interfaces from direct internet exposure; restrict access to trusted management networks or VPN.
  • Audit the Apex Central host for unexpected or recently written files, especially in web-accessible directories.
  • Monitor for and block upload attempts to Apex Central endpoints from untrusted sources at the network edge.

Detection

  • Review Apex Central and web server logs for POST/multipart upload requests from unexpected source IPs, particularly those returning success without prior authentication.
  • Alert on new or modified executable files (for example .jsp, .aspx, .php, .exe, .dll) appearing in Apex Central web or application directories.
  • Monitor for child processes spawned by the Apex Central web service (IIS/w3wp or equivalent) that are unusual for normal operation.
  • Hunt for outbound connections from the Apex Central host to unfamiliar destinations following upload activity.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2022-26871 to the Known Exploited Vulnerabilities catalog on 31 March 2022 as "Trend Micro Apex Central Arbitrary File Upload Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 21 April 2022.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-26871 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-54948Trend Micro Apex One management console OS command injectionThe on-premise Apex One management console contains an OS command injection flaw (CWE-78) that lets a remote attacker upload malicious code and run c…KEVEPSS 22%analysed9.8CVE-2020-8599Trend Micro Apex One and OfficeScan EXE allows arbitrary file write and ROOT bypassTrend Micro Apex One (2019) and OfficeScan XG server ship a vulnerable EXE file that lets a remote, unauthenticated attacker write arbitrary data to …KEVEPSS 12%analysed8.8CVE-2021-36741Trend Micro Apex One and OfficeScan unrestricted file uploadTrend Micro Apex One, Apex One as a Service, OfficeScan XG and Worry-Free Business Security 10.0 SP1 fail to properly validate input, allowing an aut…KEVEPSS 5.0%analysed8.8CVE-2020-8468Trend Micro Apex One, OfficeScan and Worry-Free agents content validation escapeTrend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) agents contain a content validation escape flaw (CWE-74)…KEVEPSS 6.2%analysed8.8CVE-2020-8467Trend Micro Apex One and OfficeScan migration tool RCEA component of the migration tool in Trend Micro Apex One (2019) and OfficeScan XG allows remote attackers to execute arbitrary code on affected inst…KEVEPSS 11%analysed7.8CVE-2021-36742Trend Micro Apex One and OfficeScan improper input validation privilege escalationTrend Micro Apex One, Apex One as a Service, OfficeScan XG and Worry-Free Business Security 10.0 SP1 contain an improper input validation flaw (CWE-2…KEVEPSS 1.5%analysed7.8CVE-2020-24557Trend Micro Apex One and Worry-Free Business Security folder manipulation privilege escalationTrend Micro Apex One and Worry-Free Business Security 10.0 SP1 on Windows allow an attacker to manipulate a product folder to temporarily disable the…KEVEPSS 2.7%analysed7.2CVE-2023-41179Trend Micro Apex One AV uninstaller module command injectionThe third-party AV uninstaller module in Trend Micro Apex One (on-prem and SaaS), Worry-Free Business Security, and Worry-Free Business Security Serv…KEVEPSS 4.3%analysed

Source: NIST National Vulnerability Database (record CVE-2022-26871), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.