Cyber Security News

Critical Trend Micro Apex One Vulnerabilities Allows Malicious Code Execution

Trend Micro has released fixes for multiple Apex One vulnerabilities, ranging from High to Critical severity, including management console issues that can lead to remote code execution (RCE).

The affected CVEs range from CVE-2025-71210 to CVE-2025-71217, with CVSS v3 scores ranging from 7.2 to 9.8.​

The February 2026 advisory lists Apex One 2019 (on‑prem) on Windows and Apex One as a Service (Trend Vision One Endpoint – Standard Endpoint Protection) on Windows as affected product lines.

Trend Micro’s remediation guidance points customers to update to the latest available builds, even if earlier patches may have addressed parts of the issue.​

Trend Micro Apex One Vulnerabilities

Two critical flaws, CVE-2025-71210 and CVE-2025-71211, are described as console directory traversal RCE vulnerabilities (CWE-22) in the Apex One management console.

These issues allow attackers to upload malicious code and execute commands on affected installations.

Trend Micro notes that exploitation requires access to the Apex One Management Console.

The company warns that externally exposed console IP addresses increase the risk and recommends applying source restrictions where they are not already in place.

The advisory also details local privilege escalation (LPE) issues affecting Windows components, including link following (CWE-59) and origin validation errors (CWE-346).

CVETypeCVSSPlatformKey Note
CVE-2025-71210Console dir traversal RCE9.8WindowsConsole access required; SaaS mitigated
CVE-2025-71211Console dir traversal RCE9.8WindowsSimilar to 71210
CVE-2025-71212Link following LPE7.8WindowsLow-privileged code execution required
CVE-2025-71213Origin validation LPE7.8WindowsLow-privileged code execution required
CVE-2025-71214Origin validation LPE7.2MacInformational; previously fixed
CVE-2025-71215TOCTOU LPE7.8MacInformational; previously fixed
CVE-2025-71216TOCTOU LPE7.8MacInformational; previously fixed
CVE-2025-71217Origin validation LPE7.8MacInformational; previously fixed

These vulnerabilities require an attacker to already have the ability to execute low-privileged code on the target endpoint.

For macOS agents, Trend Micro provides CVE references as informational, stating these were addressed earlier via ActiveUpdate/SaaS updates in mid to late 2025.

Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

Abinaya

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Critical Apache Struts Vulnerabilities Enables Remote Code Execution Attacks

Four security flaws described in the supplied Apache Struts advisories could expose affected applications to…

55 minutes ago

Former Infrastructure Engineer Sentenced for Sabotaging Employer’s Windows Network

A former infrastructure engineer has been sentenced to 32 months in federal prison for sabotaging…

1 hour ago

GitHub Copilot CLI Vulnerability Lets Attackers Steal Developer Secrets Using Encrypted Prompt Injection

A new GitHub Copilot CLI finding that could allow an attacker-controlled web page to guide…

1 hour ago

From Telemetry to Defense: How SOC and MSSP Leaders Can Build Intelligence-Led Threat Monitoring

Every function in a security operations center, from alert triage to incident response, depends on…

1 hour ago

ASOS Hacked – App Users Receive Notifications Sent by Hackers

ASOS is investigating a cyber incident after customers received an unauthorized app notification claiming hackers…

2 hours ago

Aembit Extends Access Controls to Personal AI Agents

Silver Springs, United States / Maryland, October 6th, 2026, CyberNewswire Aembit, the identity control plane…

2 hours ago