Executive brief
Trend Micro Apex One is a centralized security management platform used by organizations to protect endpoints from malware and other threats. A critical vulnerability in its management console allows an unauthorized attacker to remotely upload and run malicious code on the server. This could lead to a complete takeover of the security management system, potentially compromising the entire network of protected devices.
Technical details
An OS command injection vulnerability (CWE-78) exists in the Trend Micro Apex One (on-premise) management console. The flaw allows a remote, unauthenticated attacker to bypass security controls to upload malicious files and execute arbitrary commands with elevated privileges on the underlying operating system. The attack vector is network-based and requires no user interaction or prior authentication. This vulnerability has been observed being exploited in the wild. Trend Micro has released a patch to address this issue, and users are advised to apply it immediately.
Affected products
- Trend Micro Apex One (on-premise) management console 2019
Timeline
- 2025-08-05: disclosed: Initial disclosure by Trend Micro
- 2025-08-05: patched: Vendor advisory and patch released
- 2025-08-18: kev added: Added to CISA Known Exploited Vulnerabilities catalog
- 2025-08-18: exploited: Confirmed active exploitation in the wild