HomeIntelligenceBrief
VULNERABILITY BRIEF🟠 High Vulnerability

Critical Information Disclosure in Trend Micro Vision One Service Gateway (CVE-2025-71386) Threatens Log Data

Trend Micro disclosed CVE‑2025‑71386, a 7.7‑score vulnerability in Vision One’s Service Gateway that lets authenticated remote attackers read sensitive log data. The flaw highlights the need for robust log‑access controls and continuous audit evidence in SOC 2‑aligned environments.

LiveThreat™ Intelligence · 📅 July 30, 2026· 📰 zerodayinitiative.com
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
3 recommended
📰
Source
zerodayinitiative.com

Critical Information Disclosure in Trend Micro Vision One Service Gateway (CVE‑2025‑71386) Threatens Log Data

What It Is — A vulnerability (CVE‑2025‑71386) in the Service Gateway module of Trend Micro Vision One allows an authenticated remote attacker to read log files that contain sensitive information.

Exploitability — The flaw is exploitable over the network (AV:N) with low attack complexity (AC:L). Authentication is required (PR:L). CVSS v3.1 base score 7.7 (High). Trend Micro has released a patch.

Affected Products — Trend Micro Vision One (Service Gateway component).

Why It Matters for Compliance & Audit Readiness

  • SOC 2 CC6.1 (Logical Access) requires that log data be protected from unauthorized access; this issue shows a gap in that control.
  • Continuous control monitoring must capture evidence that logging mechanisms are hardened and that access is logged and reviewed.
  • Enterprise buyers increasingly demand proof of secure logging as part of their SOC 2 audit packages.

Recommended Actions

  • Deploy Trend Micro’s security update immediately.
  • Review and tighten file‑system permissions on all Vision One log directories to enforce least‑privilege access.
  • Enable continuous monitoring of log‑file access and integrate the alerts into your compliance evidence repository.

Source: Zero Day Initiative Advisory

📰 Original Source
http://www.zerodayinitiative.com/advisories/ZDI-26-497/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · SOC 2 Readiness

Could you prove your access controls held up here?

Credential and access failures map directly to SOC 2 access-control criteria. The Verisq AI Trust Operations platform shows where your evidence is thin before an auditor — or an attacker — finds out.

Explore the Verisq AI Trust Operations platform →