LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2022-26871: Trend Micro Apex Central Arbitrary File Upload Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 31, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Apr 21, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2022-26871 to its Known Exploited Vulnerabilities catalog on Mar 31, 2022, with a federal patch deadline of Apr 21, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

An arbitrary file upload vulnerability in Trend Micro Apex Central could allow for remote code execution.

CVE-2022-26871 is an arbitrary file upload vulnerability in Trend Micro Apex Central that could allow remote code execution. For IT and security teams running this management console, it matters because a successful exploit can give an attacker a foothold on a central security platform that often has broad visibility and control over endpoints.

Public detail is limited to the CISA description and the associated weakness; confirm exact scope, fixed builds, and deployment notes against the vendor advisory before acting.

How it works

The flaw is classified as CWE-184 (Incomplete List of Disallowed Inputs). In products that accept file uploads, this class of weakness typically means the application does not fully reject dangerous file types, extensions, or content, so an attacker can place a file the server will later treat as executable or interpretable code.

According to the CISA summary, an arbitrary file upload in Trend Micro Apex Central could lead to remote code execution. In practical terms for this product class, that usually involves an unauthenticated or insufficiently authenticated request that writes a malicious payload to a location the application or web server will process. Exact request paths, parameters, and preconditions are not provided in the given facts and must be confirmed against the vendor advisory; do not assume exploit mechanics beyond the stated arbitrary-file-upload-to-RCE outcome.

Am I affected? How to find it in your systems

Trend Micro Apex Central is typically deployed as a central management console for Trend Micro endpoint and security products, often on Windows servers in data centers or management VLANs. Inventory every host that runs Apex Central or related management components.

If you cannot determine version or configuration status locally, treat the instance as potentially affected until verified against the vendor advisory.

How to remediate

Patch first. CISA’s required action is to apply updates per vendor instructions. Obtain the security update or fixed build that addresses CVE-2022-26871 from Trend Micro, test in a representative environment, then deploy to all Apex Central instances.

If you can't patch immediately

Reduce exposure until the vendor update can be applied.

If your data may have been exposed

Actively exploited vulnerabilities of this type can lead to full compromise of the management server and, from there, to broader access or data exposure. Known ransomware use is not documented for this CVE in the provided facts. If you suspect exploitation, isolate the host, preserve logs and disk images, rotate credentials that the console could access, and follow your incident-response process. You can also run a free exposure scan of your email addresses against known breach data to see whether associated accounts appear in public breach corpora while you complete containment and recovery.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedTrend Micro · Apex Central
WeaknessCWE-184
Added to CISA KEVMar 31, 2022
Federal patch deadlineApr 21, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities