Trend Micro issued security updates for Apex One and related endpoint protection offerings to fix eight vulnerabilities, including two critical path traversal flaws in the Apex One management console tracked as CVE-2025-71210 and CVE-2025-71211. According to the vendor bulletin and CSIRT.SK, the bugs affect Apex One 2019 on-premises for Windows, Apex One SaaS for Windows, Trend Vision One Endpoint – Standard Endpoint Protection SaaS for Windows, and Apex One SaaS for Mac, and could allow an unprivileged attacker with access to the console to upload and execute malicious code.
The same update also addresses six local privilege escalation issues, CVE-2025-71212 through CVE-2025-71217, impacting scanning components and Mac agent services or mechanisms. Organizations were urged to apply Critical Patch Build 14136 for on-premises deployments and Security Agent Build 14.0.20315 for SaaS deployments immediately, while taking additional precautions if management consoles are exposed to the public internet.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
Trend Micro published a February 2026 security bulletin for Apex One and Apex One (Mac) describing fixes for eight vulnerabilities, including two critical path traversal flaws and six local privilege escalation issues. The bulletin recommends installing Critical Patch Build 14136 for on-premises deployments and Security Agent Build 14.0.20315 for SaaS deployments.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.