Bulletin Date: July 17, 2026
CVE Vulnerability Identifiers: CVE-2026-62660
Platform(s): Microsoft Windows
CVSSv3 Scores: 5.6 AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:H
Severity Rating: Medium
Summary
Trend Micro has released an update for Trend Micro Cleaner One Pro which resolves an Arbitrary File Deletion Vulnerability by updating the libraries in version 6.8.375 or higher of the software.
Affected Version(s)
| PRODUCT | AFFECTED VERSION(S) | PLATFORM | LANGUAGE(S) |
|---|---|---|---|
| Trend Micro Cleaner One Pro | 6.8.359 and below | Microsoft Windows | English |
Solution
| PRODUCT | UPDATED VERSION(S) | PLATFORM | LANGUAGE(S) |
|---|---|---|---|
| Trend Micro Cleaner One Pro | 6.8.375 | Microsoft Windows | English |
Vulnerability Details
Trend Micro Cleaner One Pro contains a vulnerability that could allow a malicious app already running on your device to trick the cleanup process into deleting a file it shouldn't have access to. This requires local access to the device — it cannot be exploited remotely. Trend Micro has received no reports nor is aware of any actual attacks against the affected product related to this vulnerability at this time.
Acknowledgment
Trend Micro would like to thank the following individual for responsibly disclosing the issue and working with Trend Micro to help protect our customers:
- Zeze and Sharkkcode with TeamT5 working with TrendAI Zero Day Initiative
Additional Assistance
Customers who have questions are encouraged to contact TrendLife Technical Support for further assistance.
External Reference
The following advisories may be found at TrendAI's Zero Day Initiative Published Advisories site:
- ZDI-CAN-28718
