Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2021-36741
Trend Micro Apex One, Apex One as a Service, and Worry-Free Business Security
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L L N U H H H 8.8 .0495 91.9 YES
AFFECTED
Product Versions Fixed
Trend Micro Apex One 2019, SaaS – —
Trend Micro OfficeScan XG SP1 – —
Trend Micro Worry-Free Business Security 10.0 SP1 – —
TIMELINE
Jul 14 Reserved by trendmicro
Jul 29 Published (CNA: trendmicro)
Nov 3 Added to CISA KEV, remediation due 2021-11-17
Description
An improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG, and Worry-Free Business Security 10.0 SP1 allows a remote attached to upload arbitrary files on affected installations. Please note: an attacker must first obtain the ability to logon to the product�s management console in order to exploit this vulnerability.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| July 14, 2021 | Reserved | Reserved by trendmicro |
| July 29, 2021 | Published | Published (CNA: trendmicro) |
| November 3, 2021 | KEV ADDED | Added to CISA KEV, remediation due 2021-11-17 |
Affected
Affected products and packages — 3 rows
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| Trend Micro | Trend Micro Apex One | — | 2019, SaaS | — |
| Trend Micro | Trend Micro OfficeScan | — | XG SP1 | — |
| Trend Micro | Trend Micro Worry-Free Business Security | — | 10.0 SP1 | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2021-36741 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.