[Japanese]

JVNDB-2026-026086

Security Update for Trend Micro Trend Vision One (July 2026)

Overview

Trend Micro Incorporated has released a security update for TrendAI Vision One Service Gateway.
Trend Micro Incorporated reported these vulnerabilities to JPCERT/CC to notify users of the solutions through JVN.
CVSS Severity (What is CVSS?)

Affected Products


Trend Micro, Inc.
  • TrendAI Vision One Service Gateway

Impact

  • Sensitive information may be obtained by a remote attacker (CVE-2025-71386).
  • A user with certain key roles may elevate its own privileges (CVE-2025-71387).
Solution

Each vulnerability has been addressed on the backend service, and no user action is required if automatic updates are enabled.
Vendor Information

Trend Micro, Inc.
CWE (What is CWE?)

CVE (What is CVE?)

  1. CVE-2025-71386
  2. CVE-2025-71387
References

  1. JVN : JVNVU#98815601
Revision History

  • [2026/07/31]
      Web page was published