CVE-2020-28578: Trend Micro Interscan Web Security Virtual Appliance
Critical severity, CVSS 9.8. EPSS: 73% chance of exploitation in the next 30 days.
A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an unauthenticated, remote attacker to send a specially crafted HTTP message and achieve remote code execution with elevated privileges.
Affected products
- Trend Micro Interscan Web Security Virtual Appliance: version 6.5 only
Published 2020-11-18. Last modified 2026-06-17.