Trend Micro disclosed multiple critical vulnerabilities in the Apex One management console that could let remote attackers upload malicious code and execute commands on affected systems. The issues include CVE-2025-54948, a CVSS 9.8 directory traversal flaw in the console that can be exploited without authentication because of improper validation of a user-supplied path before file operations; successful exploitation can lead to arbitrary code execution in the context of IUSR. Public reporting also identified related critical flaws CVE-2025-71210 and CVE-2025-71211, which similarly enable remote code upload and command execution through different executables in the console.
Trend Micro said the vulnerabilities were reported through the Zero Day Initiative and released updates and guidance for affected customers. The vendor said SaaS deployments were already mitigated and require no customer action, but warned that exploitation depends on access to the Apex One Management Console, which listens on TCP 8080 and 4343 by default in the case of the traversal issue. Organizations with externally exposed console IPs were urged to apply patches and restrict source access or otherwise limit exposure until remediation is complete.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Trend Micro disclosed two critical Apex One management console vulnerabilities that could let a remote attacker upload malicious code and execute commands on affected installations. The company said the issues were responsibly disclosed through the Zero Day Initiative, SaaS versions had already been mitigated, and customers with exposed console IPs should apply source restrictions if needed.
TrendAI Apex One console vulnerability CVE-2025-54948 was publicly disclosed as a critical unauthenticated remote code execution issue caused by improper path validation before file operations. The vendor issued an update to remediate the flaw.
The directory traversal remote code execution flaw later tracked as CVE-2025-54948 was reported to the vendor on 2025-08-26. The advisory credits Charles Yang of CoreCloud Tech with the discovery.
A critical unauthenticated OS command injection vulnerability in the Trend Micro Apex One on-premise management console, tracked as CVE-2025-54987, was described as allowing remote attackers to upload malicious code and execute arbitrary system commands. The reference says Trend Micro published an advisory and fix tool, and notes the issue is closely related to CVE-2025-54948 but affects a different CPU architecture.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
tenable.com
Open sourcetenable.com
Open sourcezerodayinitiative.com
Open sourcezeropath.com
Open sourcezeropath.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.