Trend Micro patched two critical remote code execution vulnerabilities in Apex One affecting Windows environments, both caused by path traversal weaknesses in the Apex One management console: CVE-2025-71210 and CVE-2025-71211. Trend Micro stated exploitation requires an attacker to have access to the management console, and warned organizations with consoles exposed to the internet to apply mitigations such as source/IP restrictions and to update to the latest builds; the fixes include updates for SaaS deployments and Critical Patch Build 14136 for affected on-prem installations.
Canada’s Centre for Cyber Security issued advisory AV26-168 urging administrators to apply Trend Micro’s updates for Apex One (on-premise), Apex One as a Service (SaaS), and Trend Vision One Endpoint / Standard Endpoint Protection (SaaS). Neither advisory indicated confirmed exploitation in the wild for these specific CVEs at the time of publication, but the vendor and reporting highlighted that Apex One vulnerabilities have been actively exploited in prior campaigns, reinforcing the need for rapid patching and exposure reduction of management interfaces.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
On February 25, 2026, the Canadian Centre for Cyber Security published notice AV26-168 highlighting Trend Micro's advisory and urging users and administrators to review the guidance and apply necessary updates. The notice identified affected products including Apex One on-premises, Apex One as a Service, and Trend Vision One Endpoint.
On February 24, 2026, Trend Micro published a security advisory for Apex One and related products covering two critical directory traversal vulnerabilities in the management console that could lead to remote code execution, along with additional high-severity flaws. The advisory said SaaS versions had already been mitigated and released Critical Patch Build 14136 for affected on-premises systems.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcecybersecuritynews.com
Open sourcesecurityaffairs.com
Open sourcebleepingcomputer.com
Open sourcecyber.gc.ca
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.