HomeSecurityTrend Micro: Critical vulnerabilities in Apex One

Trend Micro: Critical vulnerabilities in Apex One

Trend Micro has announced the patching of two critical vulnerabilities in its Apex One endpoint protection platform that could allow remote code execution (RCE) on vulnerable Windows systems. The fixes come at a time of increased pressure for cybersecurity vendors as protection tools have become a prime target for attackers seeking broad access to corporate networks.

Trend Micro Apex One

Apex One is a core product in the Japanese company's portfolio, offering detection and response against malware, spyware, attacks with "living off the land" tools and known vulnerabilities. Due to its deep integration into corporate endpoints, any serious vulnerability is particularly critical.

CVE-2025-71210 and CVE-2025-71211: Path traversal with RCE implications

The first vulnerability, CVE-2025-71210, is attributed to a path traversal vulnerability in the Apex One management console. An unauthorized attacker could, under certain conditions, execute malicious code on unpatched systems. The second, CVE-2025-71211, concerns a similar mechanism in a different executable in the same console, with a similar range of effects.

See also: Claude Code: Vulnerabilities allow RCE attacks and API key theft

According to the company's security advisory , successful exploitation requires access to the Management Console . This means that organizations that have publicly exposed their console IP address are at increased risk, especially if they don't implement source-based access restrictions or other isolation mechanisms.

Hotfixes and Critical Patch Build 14136

To address the two RCEs, Trend Micro has released fixes to the SaaS version of Apex One and released Critical Patch Build 14136 for on-premises installations. This build not only addresses the two critical vulnerabilities, but also resolves two high-severity privilege escalation vulnerabilities in the Windows agent, as well as four vulnerabilities affecting the agent on macOS.

The company emphasizes that while the exploit requires specific prerequisites, customers should proceed with the upgrade immediately. Practice shows that attackers analyze patches to develop exploit code within a few days of publication.

Trend Micro: Critical vulnerabilities in Apex One

History of active exploitation and zero-days

Although the two new vulnerabilities have not been identified as actively exploited, the history of Apex One highlights the risk. In August 2025, Trend Micro warned of an actively exploited RCE (CVE-2025-54948), while in 2022 and 2023 it encountered zero-day attacks (CVE-2022-40139 and CVE-2023-41179 respectively) that were exploited in real attacks before patches were released.

See also: Zyxel: Critical RCE vulnerability affects many routers

The repeated targeting of endpoint security is not accidental. When an attacker compromises the system that is supposed to protect the network, they gain a strategic advantage: the ability to disable defense mechanisms, hide activity, and move laterally with reduced risk of detection.

CISA monitoring and broader implications

CISA is currently tracking ten Apex vulnerabilities that have either been exploited in the wild or remain actively exploited. The inclusion of a vulnerability on the agency's Known Exploited Vulnerabilities list increases the pressure for rapid remediation, especially in critical infrastructure.

The case highlights a broader problem in the industry: are cybersecurity tools becoming a “single point of failure.” As they amass administrator privileges and deep visibility into the system, they are an attractive target for state- and financially motivated groups.

Trend Micro: Critical vulnerabilities in Apex One

What should organizations do?

In addition to immediately installing patches, experts recommend restricting access to the management console via VPN or IP allowlisting, enabling multi-factor authentication , and constantly monitoring logs for suspicious activity. Regular incident response drills can also reduce response time in the event of a breach.

See also: CISA: FileZen vulnerability in KEV Catalog

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Trend Micro’s new warning serves as a reminder that even defenses need to be constantly monitored and updated. In a landscape where attacks are becoming increasingly automated and targeted, speed of patching remains a critical factor in cyber resilience.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS