VORANT. Threat Intelligence Sign in Get the full feed

Trend Micro Apex One flaw exploited in wild

high vulnerability technology

Trend Micro Apex One and Apex One SaaS contain multiple vulnerabilities, one of which (CVE-2022-40139) is being actively exploited, requiring urgent patching.

IPA (Japan's Information-technology Promotion Agency) issued an advisory regarding multiple vulnerabilities in Trend Micro Apex One and Apex One SaaS, endpoint security products. The vulnerabilities carry varying CVSS v3 and v2 scores, with severities ranging from moderate to important, the highest reaching 8.2/6.4.

Of particular concern is CVE-2022-40139, which Trend Micro has confirmed is being actively exploited in the wild. IPA urges administrators to apply vendor-supplied patches as soon as possible. Additional vulnerabilities are listed with lower severity ratings, and mitigations/workarounds are referenced from the vendor's official advisory pages for organizations unable to patch immediately.

Mentioned in this report

Vulnerabilities CVE-2022-40139KEV

Source reporting: https://www.ipa.go.jp/archive/security/security-alert/2022/20220913-jvn.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free