Trend Micro Apex One Unauthenticated RCE | MSSP Advisory

Critical
DateMay 22, 2026
📋Executive Summary
Trend Micro patched CVE-2024-36308, a critical zero-day vulnerability in Apex One that allows unauthenticated remote code execution on Windows systems. Attackers are actively exploiting this flaw to execute arbitrary code without authentication through the product's web console. The vulnerability affects Trend Micro Apex One versions prior to 2019 Service Pack 1 Critical Patch b13959.
⚠️Why It Matters for MSSPs
If you run Trend Micro Apex One in your own environment, attackers can gain complete control of your endpoint management infrastructure without credentials. Your clients running unpatched Apex One installations are sitting ducks for immediate compromise, and you have a duty to warn them because this is being exploited right now in the wild.
📬

Get notified when client-ready advisories like this are published each week.

Join the MSSP Watchlist →
🏷️Threat Category
Zero-Day

Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.