Known vulnerabilities in Apex One SP1 Patch 2 b12902

Software: Apex One
Version: SP1 Patch 2 b12902
Software CPE: cpe:2.3:a:trend_micro:apex_one:*:*:*:*:*:*:*:*
Total vulnerabilities: 27
Public exploits: 1
Known exploited (KEV): 2
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting Apex One version SP1 Patch 2 b12902 Apex One SP1 Patch 2 b12902 is affected by 27 vulnerabilities: 4 critical, 2 high, 2 medium, 19 low Critical High Medium Low

Vulnerabilities (27)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU132106 - Relative Path Traversal
CVE-2026-34926
CWE-23 High
No
Exploited
SP1 CP 18012, SP1 17079 22.05.2026 SB2026052201
#VU132107 - Origin Validation Error
CVE-2026-34927
CWE-346 Low
No
No
SP1 CP 18012, SP1 17079 22.05.2026 SB2026052201
#VU132108 - Origin Validation Error
CVE-2026-34928
CWE-346 Low
No
No
SP1 CP 18012, SP1 17079 22.05.2026 SB2026052201
#VU132109 - Origin Validation Error
CVE-2026-34929
CWE-346 Low
No
No
SP1 CP 18012, SP1 17079 22.05.2026 SB2026052201
#VU132110 - Origin Validation Error
CVE-2026-34930
CWE-346 Low
No
No
SP1 CP 18012, SP1 17079 22.05.2026 SB2026052201
#VU132111 - Origin Validation Error
CVE-2026-45206
CWE-346 Low
No
No
SP1 CP 18012, SP1 17079 22.05.2026 SB2026052201
#VU132112 - Origin Validation Error
CVE-2026-45207
CWE-346 Low
No
No
SP1 CP 18012, SP1 17079 22.05.2026 SB2026052201
#VU132113 - Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2026-45208
CWE-367 Low
No
No
SP1 CP 18012, SP1 17079 22.05.2026 SB2026052201
#VU123219 - Origin Validation Error
CVE-2025-71213
CWE-346 Low
No
No
CP 14136 24.02.2026 SB2026022465
#VU123218 - Improper Link Resolution Before File Access ('Link Following')
CVE-2025-71212
CWE-59 Low
No
No
CP 14136 24.02.2026 SB2026022465
#VU123217 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2025-71211
CWE-22 Critical
No
No
CP 14136 24.02.2026 SB2026022465
#VU123216 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2025-71210
CWE-22 Critical
No
No
CP 14136 24.02.2026 SB2026022465
#VU116609 - Use After Free
CVE-2025-49844
CWE-416 Medium
Public exploit available
No
- 06.10.2025 SB2025100629
SB2025100633
SB2025100709
and 56 more
#VU113669 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2025-54987
CWE-78 Critical
No
No
- 06.08.2025 SB2025080616
#VU113667 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2025-54948
CWE-78 Critical
No
Exploited
- 06.08.2025 SB2025080616
#VU110678 - Improper Link Resolution Before File Access ('Link Following')
CVE-2025-49157
CWE-59 Low
No
No
CP 14002 09.06.2025 SB2025060965
#VU110677 - Improper Link Resolution Before File Access ('Link Following')
CVE-2025-49156
CWE-59 Low
No
No
CP 14002 09.06.2025 SB2025060965
#VU110676 - Uncontrolled Search Path Element
CVE-2025-49155
CWE-427 High
No
No
CP 14002 09.06.2025 SB2025060965
#VU110675 - Untrusted Search Path
CVE-2025-49158
CWE-426 Low
No
No
CP 14002 09.06.2025 SB2025060965
#VU110674 - Improper Access Control
CVE-2025-49154
CWE-284 Low
No
No
CP 14002 09.06.2025 SB2025060965
SB2025060966


Showing elements 1 - 20 out of 27