Overview

Trend Micro Incorporated has released a security update for TrendAI Vision One Service Gateway.

Products Affected

  • TrendAI Vision One Service Gateway

Description

Trend Micro Incorporated has released a security update for TrendAI Vision One Service Gateway.

Impact

  • Sensitive information may be obtained by a remote attacker (CVE-2025-71386).
  • A user with certain key roles may elevate its own privileges (CVE-2025-71387).

Solution

Each vulnerability has been addressed on the backend service, and no user action is required if automatic updates are enabled.

Vendor Status
References

JPCERT/CC Addendum

Vulnerability Analysis by JPCERT/CC
Credit

Trend Micro Incorporated reported these vulnerabilities to JPCERT/CC to notify users of the solutions through JVN.

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE
JVN iPedia

expand_less