CVE-2022-26871

CVE Published 2022-03-29
Related CWE(s) CWE-345: Insufficient Verification of Data Authenticity
Related Vendor(s) trendmicro
Related Product(s) apex_one, apex_central
Exploitation Reported (CISA KEV) 2022-03-31
CVSS 3 Base Score 9.8 (CRITICAL)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector NETWORK

An arbitrary file upload vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to upload an arbitrary file which could lead to remote code execution.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References