A critical remote code execution vulnerability, tracked as CVE-2025-69258, was discovered in Trend Micro Apex Central (on-premise), allowing unauthenticated attackers to load a malicious DLL into the MsgReceiver.exe process and execute code with SYSTEM privileges. The flaw, along with two related vulnerabilities (CVE-2025-69259 and CVE-2025-69260), was privately reported by Tenable researchers and affects all previous releases of Apex Central prior to Critical Patch Build 7190. Exploitation requires only network access to the vulnerable system, and technical details as well as proof-of-concept exploits have been publicly released.
Trend Micro has issued a critical patch to address these vulnerabilities and strongly urges customers to update to the latest build immediately. The company also recommends reviewing remote access policies and perimeter security to mitigate potential exploitation. The vulnerabilities can be triggered by sending specially crafted messages to the MsgReceiver.exe process, which listens on TCP port 20001, with CVE-2025-69258 enabling code execution and the others causing denial of service. No affected product versions were explicitly listed in the CVE database at the time of disclosure, but all prior releases are considered vulnerable.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
As of 2026-01-09, reporting from Trend Micro and other coverage indicated there was no confirmed evidence that CVE-2025-69258 had been exploited in the wild. Despite that, public PoC availability increased the risk to internet-facing Apex Central servers.
On 2026-01-08, CVE-2025-69258 was publicly published as a critical Trend Micro Apex Central remote code execution vulnerability with a CVSS score of 9.8. Advisories emphasized that the flaw is network-exploitable without authentication or user interaction and urged customers to apply Trend Micro's updates.
On 2026-01-07, Tenable publicly disclosed the Apex Central vulnerabilities it had privately reported, including technical details and proof-of-concept exploits. The disclosure showed that specially crafted messages to MsgReceiver.exe on TCP port 20001 could let unauthenticated attackers load a malicious DLL and execute code as SYSTEM.
On 2026-01-07, Trend Micro released Build 7190 for on-premises Apex Central to fix three remotely exploitable vulnerabilities affecting earlier versions. The most severe, CVE-2025-69258, allows unauthenticated remote code execution as SYSTEM; CVE-2025-69259 and CVE-2025-69260 can cause denial of service.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
arcticwolf.com
Open sourcearcticwolf.com
Open sourcecsoonline.com
Open sourcecvefeed.io
Open sourcehelpnetsecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.