Trend Micro Apex One

Trend Micro · current 18040

Are you Trend Micro? Claim this page

The current version of Trend Micro Apex One is 18040 (as of 30/07/2026). patchletter checks the official source daily and emails you new releases.

Actively exploited vulnerabilities

The US cybersecurity agency CISA lists these vulnerabilities in its catalog of Known Exploited Vulnerabilities. What CISA does not carry does not appear in this list — even where it is being exploited.

  • CVE-2020-8599Trend Micro Apex One and OfficeScan Authentication Bypass Vulnerability

    9.8 critical · over the network, without login · CISA deadline was 3 May 22

  • CVE-2025-54948Trend Micro Apex One OS Command Injection Vulnerability

    9.8 critical · over the network, without login · CISA deadline was 8 Sept 25

  • CVE-2021-36741Trend Micro Multiple Products Improper Input Validation Vulnerability

    8.8 high · over the network, with a basic account · CISA deadline was 17 Nov 21

  • CVE-2020-8468Trend Micro Multiple Products Content Validation Escape Vulnerability

    8.8 high · over the network, with a basic account · CISA deadline was 3 May 22

  • CVE-2020-8467Trend Micro Apex One and OfficeScan Remote Code Execution Vulnerability

    8.8 high · over the network, with a basic account · CISA deadline was 3 May 22

  • CVE-2021-36742Trend Micro Multiple Products Improper Input Validation Vulnerability

    7.8 high · locally only, with a basic account · CISA deadline was 17 Nov 21

  • CVE-2020-24557Trend Micro Multiple Products Improper Access Control Vulnerability

    7.8 high · locally only, with a basic account · CISA deadline was 3 May 22

  • CVE-2022-40139Trend Micro Apex One and Apex One as a Service Improper Validation Vulnerability

    7.2 high · over the network, with admin rights only · CISA deadline was 6 Oct 22

  • CVE-2023-41179Trend Micro Apex One and Worry-Free Business Security Remote Code Execution Vulnerability

    7.2 high · over the network, with admin rights only · CISA deadline was 12 Oct 23

  • CVE-2026-34926Trend Micro Apex One (On-Premise) Directory Traversal Vulnerability

    6.7 medium · locally only, with admin rights only · CISA deadline was 4 Jun

Source: CISA KEV. The CVE is matched to the product automatically — when in doubt, the linked NVD entry applies.

BSI security advisories

Advisories the German BSI (CERT-Bund) published for this product. Whether your version is affected is stated in the advisory itself.

All BSI advisories →

Trend Micro Apex One at a glance

Trend Micro Apex One is Trend Micro's endpoint security product for Windows and macOS workstations. It combines antivirus scanning, behavioural analysis, exploit and ransomware protection, device control and virtual patching, and runs either as an on-premises server or as a SaaS offering, with central administration typically through Apex Central.

The on-premises edition is not maintained as a conventional version series. Instead it ships service packs plus a continuous stream of critical patches and product patches identified by build numbers and published in the Download Center. Critical patches bundle accumulated fixes and regularly close vulnerabilities in the management server or the agent; clients additionally receive hotfixes and automatically distributed pattern updates.

Follow the vendor's installation order when applying them: server first, then agents. Patches are published per language, so the matching language build has to be selected deliberately. A restart of the server and of the endpoints is often required, as is a database backup beforehand. Because Apex One flaws have been exploited in the wild, critical patches deserve prompt scheduling.

Version history & changelog · as detected by patchletter

VersionChannelDateNotes
18040STABLE30/07/2026Release notes →
18020STABLE04/06/2026Release notes →
18012STABLE07/05/2026Release notes →
17079STABLE26/03/2026Release notes →
14136STABLE27/11/2025Release notes →

Frequently asked questions

What is the latest version of Trend Micro Apex One?
Trend Micro Apex One 18040, released 30/07/2026. patchletter checks the vendor's official source daily for new releases.
Where can I find the Trend Micro Apex One release notes?
The version history above links to the vendor's official release notes where the vendor publishes them. patchletter deliberately stores no vendor full texts.
How do I get notified about new Trend Micro Apex One updates?
Tick Trend Micro Apex One off in the catalogue and leave your address. From then on new versions go out by email — one at a time, or bundled in the daily or weekly digest.

An email as soon as a new Trend Micro Apex One version ships

We reconcile the vendor source daily. When a new version appears, it lands in your inbox right away or bundled as a digest. The update email is free and ends with one click. Alerts about vulnerabilities and end of support are part of patchletter Pro.

Embed this badge

The badge shows the current Trend Micro Apex One version and keeps it up to date. Anyone may embed it, no account needed.

Trend Micro Apex One badge
[![Trend Micro Apex One](https://patchletter.com/badge/trend-micro-apex-one.svg)](https://patchletter.com/en/software/trend-micro-apex-one)
https://patchletter.com/badge/trend-micro-apex-one.svg

Also available: ?v=eol (end of support) and ?v=cve (actively exploited).

Related tools in Industry software (DACH)