CVE-2016-3987: Trend Micro Password Manager

Critical severity, CVSS 9.8. EPSS: 22.3% chance of exploitation in the next 30 days.

The HTTP server in Trend Micro Password Manager allows remote web servers to execute arbitrary commands via the url parameter to (1) api/openUrlInDefaultBrowser or (2) api/showSB.

Affected products

  • Trend Micro Password Manager: affected versions not specified

Published 2016-04-12. Last modified 2026-06-17.