CVE-2017-14092: Trend Micro Scanmail

High severity, CVSS 8.8. EPSS: 0.9% chance of exploitation in the next 30 days.

The absence of Anti-CSRF tokens in Trend Micro ScanMail for Exchange 12.0 web interface forms could allow an attacker to submit authenticated requests when an authenticated user browses an attacker-controlled domain.

Affected products

Published 2017-12-16. Last modified 2026-06-17.