Skip to main content

CVE-2021-36741

8.8
HIGHCVSS v3.1 Base Score
0.66%
LOW RiskEPSS (72nd percentile)
KEV

An improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG, and Worry-Free Business Security 10.0 SP1 allows a remote attached to upload arbitrary files on affected installations. Please note: an attacker must first obtain the ability to logon to the product�s management console in order to exploit this vulnerability.

Published: 7/29/2021
Modified: 10/31/2025
Back to CVE Lookup

ACTIVELY EXPLOITED IN THE WILD

This vulnerability is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Vulnerability Name:

Trend Micro Multiple Products Improper Input Validation Vulnerability

Vendor / Product:

Trend Micro Apex One, Apex One as a Service, and Worry-Free Business Security

Required Action:

Apply updates per vendor instructions.

Due Date: 11/17/2021(OVERDUE)
Added to KEV:

11/3/2021

Notes:

https://success.trendmicro.com/dcx/s/solution/000287819?language=en_US, https://success.trendmicro.com/dcx/s/solution/000287820?language=en_US; https://nvd.nist.gov/vuln/detail/CVE-2021-36741

Vulnerability Summary

CVSS v3 Score

8.8HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS v2 Score

6.5

AV:N/AC:L/Au:S/C:P/I:P/A:P

EPSS Score (Exploitation Probability)

0.66%LOW Exploitation Risk
72nd percentile

This vulnerability has a 0.66% probability of being exploited in the next 30 days, ranking higher than 72% of all scored CVEs.

CWE Classification

Related Vulnerabilities

Same Weakness Type(CWE-434)

CVE-2025-13374CRITICAL 9.8

The Kalrav AI Agent plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the kalrav_upload_file AJAX action in all versions up to, and including, 2.3.3. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

1/24/2026
CVE-2026-1331CRITICAL 9.8

MeetingHub developed by HAMASTAR Technology has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.

1/22/2026
CVE-2025-55251LOW 3.1

HCL AION is affected by an Unrestricted File Upload vulnerability. This can allow malicious file uploads, potentially resulting in unauthorized code execution or system compromise.

1/19/2026
CVE-2022-50893CRITICAL 9.8

VIAVIWEB Wallpaper Admin 1.0 contains an unauthenticated remote code execution vulnerability in the image upload functionality. Attackers can upload a malicious PHP file through the add_gallery_image.php endpoint to execute arbitrary code on the server.

1/13/2026
CVE-2025-15503HIGH 7.3

A security flaw has been discovered in Sangfor Operation and Maintenance Management System up to 3.0.8. The impacted element is an unknown function of the file /fort/trust/version/common/common.jsp. Performing a manipulation of the argument File results in unrestricted upload. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

1/10/2026

Similar SeverityHIGH