Critical remote code execution (RCE) vulnerabilities via command injection in the Trend Micro Apex Oneare currently being actively exploited by malicious actors.
See also: Trend Micro patches multiple vulnerabilities

The company confirmed that it observed at least one instance of an attempted exploitation in production environments, which led to the immediate release of emergency mitigation tools.
Two critical vulnerabilities have been identified in Trend Micro Apex One (on-premise) systems, designated as CVE-2025-54948 and CVE-2025-54987. Both vulnerabilities carry a CVSS score of 3.1 9.4, indicating maximum severity. These command execution vulnerabilities, classified under CWE-78: OS Command Injection, allow pro-authenticated remote attackers to upload malicious code and execute arbitrary commands on affected installations.
The vulnerabilities specifically target version 14039 and below on Windows platforms. CVE-2025-54987 represents essentially the same vulnerability as CVE-2025-54948 but targets different CPU architectures, broadening the attack surface.
Security researchers from the Trend Micro team and Jacky Hsieh from CoreCloud Tech, working with the Trend Zero Day Initiative, are responsible for uncovering these critical security vulnerabilities.
See also: Hackers actively exploit critical RCE in WordPress Alone
The malicious agent requires attackers to have access to the Trend Micro Apex One management console, making organizations with externally exposed console IP addresses particularly vulnerable. However, the pro-authenticated nature of these exploits means that once attackers gain initial access, they can escalate privileges and execute system-wide commands without additional authentication barriers.

Trend Micro has released an emergency tool named FixTool_Aug2025.exe with SHA-256 hash c945a885a31679a913802a2aefde52b672bb2c8ac98bbed52b723e6733c0eadc to provide immediate protection against known exploits. This short-term mitigation fully protects against current attack methods but temporarily disables the Remote Install Agent for deploying agents from the management console.
Organizations using Trend Micro Apex One as a Service and Trend Vision One Endpoint Security received automatic protection through mitigations deployed on July 31, 2025, with no service interruption. A full Critical Update is expected to be released in mid-August 2025, which will restore Remote Install Agent functionality while maintaining security protections.
See also: CISA warns of PaperCut RCE vulnerability exploitation
Security experts strongly recommend implementing the emergency tool immediately, especially for organizations with management consoles exposed to the internet, and implementing additional departmental networking and access controls as defense-in-depth measures.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
