Release Date: July 22, 2026
CVE Identifier: CVE-2026-67212
Platform(s): Microsoft Windows
CVSS v3.1 Score: 7.0 (AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H)
Severity Rating: High
Summary
Trend Micro published version 6.0.1036 of Trend Micro VPN on July 22, 2026, which addresses a vulnerability that could allow local privilege escalation under special circumstances due to an uncontrolled search path element.
Affected Version(s)
| Product | Affected Version(s) | Platform | Language(s) |
|---|---|---|---|
| Trend Micro VPN | 6.0.1028 and below | Windows | English |
Solution
Trend Micro has released an update that resolves the issue.
| Product | Updated Version(s) | Platform | Language(s) |
|---|---|---|---|
| Trend Micro VPN | 6.0.1036 | Windows | English |
For step-by-step instructions on updating your app, see How to Upgrade Trend Micro VPN App to the Latest Version.
Vulnerability Details
Trend Micro VPN, version 6.0.1028 and below, is vulnerable to a local privilege escalation issue related to an uncontrolled search path element. A low-privileged local user who exploits the vulnerability could cause a specific module to be loaded into a Trend Micro VPN process running with SYSTEM privileges, resulting in local privilege escalation.
Trend Micro has received no reports nor is aware of any actual attacks against the affected product related to this vulnerability at this time.
Mitigating Factors
None identified. Customers are advised to ensure they always have the latest version of the program.
Acknowledgement
Trend Micro would like to thank Xavier DANEST working with Trend Micro's Zero Day Initiative (ZDI) for responsibly disclosing this issue and working with Trend Micro to help protect our customers.
External Reference
- ZDI-CAN-29830
Additional Assistance
Customers who have questions are encouraged to contact Trend Micro Technical Support for further assistance.
