# Trend Micro Apex One flaw actively exploited

Published: 2022-09-12 · Severity: high
Canonical: https://vorant.io/reports/4a88d6de-0b40-5bb4-bf06-7c0b4c00e876/trend-micro-apex-one-flaw-actively-exploited

> CVE-2022-40139 in Trend Micro Apex One is being actively exploited, prompting Japan's IPA to urge immediate patching.

Japan's IPA issued an advisory covering multiple vulnerabilities in Trend Micro Apex One and Apex One SaaS, an endpoint security product. Among the flaws, CVE-2022-40139 has reportedly been exploited in the wild according to the vendor, and IPA urges administrators to apply patches as soon as possible.

## Mentioned in this report

- Vulnerabilities: CVE-2022-40139 (KEV)

Source reporting: https://www.ipa.go.jp/archive/security/security-alert/2022/20220913-jvn.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/4a88d6de-0b40-5bb4-bf06-7c0b4c00e876/trend-micro-apex-one-flaw-actively-exploited.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
