Views:

Bulletin Date: July 17, 2026

CVE Vulnerability Identifiers: CVE-2026-62660

Platform(s): Microsoft Windows

CVSSv3 Scores: 5.6 AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:H

Severity Rating: Medium

Summary

Trend Micro has released an update for Trend Micro Cleaner One Pro which resolves an Arbitrary File Deletion Vulnerability by updating the libraries in version 6.8.375 or higher of the software.

Affected Version(s)

PRODUCT AFFECTED VERSION(S) PLATFORM LANGUAGE(S)
Trend Micro Cleaner One Pro 6.8.359 and below Microsoft Windows English

Solution

PRODUCT UPDATED VERSION(S) PLATFORM LANGUAGE(S)
Trend Micro Cleaner One Pro 6.8.375 Microsoft Windows English

Vulnerability Details

Trend Micro Cleaner One Pro contains a vulnerability that could allow a malicious app already running on your device to trick the cleanup process into deleting a file it shouldn't have access to. This requires local access to the device — it cannot be exploited remotely. Trend Micro has received no reports nor is aware of any actual attacks against the affected product related to this vulnerability at this time.

Acknowledgment

Trend Micro would like to thank the following individual for responsibly disclosing the issue and working with Trend Micro to help protect our customers:

  • Zeze and Sharkkcode with TeamT5 working with TrendAI Zero Day Initiative

Additional Assistance

Customers who have questions are encouraged to contact TrendLife Technical Support for further assistance.

External Reference

The following advisories may be found at TrendAI's Zero Day Initiative Published Advisories site:

  • ZDI-CAN-28718
Add a comment