HomeIntelligenceBrief
VULNERABILITY BRIEF🟡 Medium Vulnerability

Critical Arbitrary File Deletion in Trend Micro Cleaner One Pro (CVE‑2026‑62660) Threatens Endpoint Integrity

Trend Micro disclosed CVE‑2026‑62660, a local flaw that lets low‑privileged code delete arbitrary files via the Cleaner One Pro junk‑file service. The bug highlights the need for SOC 2‑aligned vulnerability‑management evidence and continuous patch monitoring.

LiveThreat™ Intelligence · 📅 July 30, 2026· 📰 zerodayinitiative.com
🟡
Severity
Medium
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
3 recommended
📰
Source
zerodayinitiative.com

Critical Arbitrary File Deletion in Trend Micro Cleaner One Pro (CVE‑2026‑62660) Threatens Endpoint Integrity

What It Is — Trend Micro’s Cleaner One Pro contains a flaw in its “Junk Files Cleanup” routine that lets a low‑privileged attacker create a junction point and force the service, which runs as SYSTEM, to delete arbitrary files.

Exploitability — Local‑only; an attacker must already have the ability to run low‑privileged code. No public exploit code has been released, but the vulnerability is fully disclosed and patched. CVSS 5.6 (AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:H).

Affected Products — Trend Micro Cleaner One Pro (all versions prior to the July 2026 security update).

Why It Matters for Compliance & Audit Readiness

  • SOC 2 CC6.1 (Vulnerability Management) requires documented evidence that known software flaws are remediated promptly; a local file‑deletion bug can be a control‑gap indicator during an audit.
  • Continuous control monitoring must capture patch‑deployment status for endpoint tools; missing evidence can trigger “control not operating effectively” findings.
  • Enterprise buyers increasingly demand proof (e.g., audit‑ready logs) that endpoint‑security products are kept up‑to‑date, especially when the product runs with SYSTEM privileges.

Recommended Actions

  • Deploy Trend Micro’s July 2026 update (TMKA‑13319) across all managed endpoints.
  • Map the vulnerability to SOC 2 CC6.1 and CC7.2 (Change Management) controls; record patch‑installation timestamps in your configuration‑management database (CMDB).
  • Enable continuous monitoring of endpoint‑security agent versions and generate audit‑ready reports that show compliance with the patch schedule.
  • Conduct a post‑patch validation scan to confirm the junction‑creation path is no longer exploitable.

Source: Zero Day Initiative advisory ZDI‑26‑496

📰 Original Source
http://www.zerodayinitiative.com/advisories/ZDI-26-496/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →