# Trend Micro Apex One flaw exploited in wild

Published: 2022-09-12 · Severity: high · Sectors: technology
Canonical: https://vorant.io/reports/4a88d6de-0b40-5bb4-bf06-7c0b4c00e876/trend-micro-apex-one-flaw-exploited-in-wild

> Trend Micro Apex One and Apex One SaaS contain multiple vulnerabilities, one of which (CVE-2022-40139) is being actively exploited, requiring urgent patching.

IPA (Japan's Information-technology Promotion Agency) issued an advisory regarding multiple vulnerabilities in Trend Micro Apex One and Apex One SaaS, endpoint security products. The vulnerabilities carry varying CVSS v3 and v2 scores, with severities ranging from moderate to important, the highest reaching 8.2/6.4.

Of particular concern is CVE-2022-40139, which Trend Micro has confirmed is being actively exploited in the wild. IPA urges administrators to apply vendor-supplied patches as soon as possible. Additional vulnerabilities are listed with lower severity ratings, and mitigations/workarounds are referenced from the vendor's official advisory pages for organizations unable to patch immediately.

## Mentioned in this report

- Vulnerabilities: CVE-2022-40139 (KEV)

Source reporting: https://www.ipa.go.jp/archive/security/security-alert/2022/20220913-jvn.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/4a88d6de-0b40-5bb4-bf06-7c0b4c00e876/trend-micro-apex-one-flaw-exploited-in-wild.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
