Junglewise Threat Intelligence

CVE-2025-71210: Trend Micro Apex One directory traversal in management console

CVE-2025-71210 · Severity: critical · CVSS 9.8 · Published 2026-05-21

Technologies: Trend Micro Trend Vision One Endpoint - Standard Endpoint Protection. Vendors: Trend Micro.

Executive brief

A critical vulnerability in the Trend Micro Apex One management console allows remote attackers to upload and execute malicious code. Apex One is a centralized security management platform used to protect corporate endpoints; an exploit could lead to full system compromise and unauthorized access to the management server. While SaaS versions have been automatically updated, on-premises customers must apply the latest patches to prevent potential remote command execution.

Technical details

A directory traversal vulnerability (CWE-22) exists in the Trend Micro Apex One management console due to improper validation of user-supplied strings before they are used in system calls. The flaw is accessible via the console's default listening ports (TCP 8080 and 4343) and does not require authentication. An attacker can exploit this to upload malicious files and execute arbitrary commands in the context of the IUSR account. Trend Micro has released Critical Patch Build 14136 for on-premises installations and has mitigated the issue for SaaS customers.

Affected products

  • Trend Micro Apex One 2019 (On-prem) Windows; SaaS versions prior to Security Agent Build 14.0.20315
  • Trend Micro Trend Vision One Endpoint - Standard Endpoint Protection SaaS Windows versions prior to Security Agent Build 14.0.20315

Timeline

  • 2025-09-11: disclosed: Vulnerability reported to vendor via Zero Day Initiative
  • 2026-03-03: patched: Coordinated public release of advisory and patches
  • 2026-05-21: advisory: NVD publication date

References

Related threats