Junglewise Threat Intelligence

CVE-2025-71211: Trend Micro Apex One directory traversal in management console

CVE-2025-71211 · Severity: critical · CVSS 9.8 · Published 2026-05-21

Technologies: Trend Micro Trend Vision One Endpoint - Standard Endpoint Protection. Vendors: Trend Micro.

Executive brief

Trend Micro Apex One is a centralized security management platform used to protect corporate endpoints. A vulnerability in its management console allows a remote attacker to upload malicious code and execute commands on the server without needing a username or password. This could lead to a complete takeover of the security management server and potential disruption of endpoint protections.

Technical details

A directory traversal vulnerability (CWE-22) exists in the Trend Micro Apex One management console due to improper validation of user-supplied strings before they are used in system calls. The flaw is located within a specific executable in the console, which typically listens on TCP ports 8080 and 4343. An unauthenticated remote attacker can exploit this by sending a specially crafted request to upload malicious code and execute it in the context of the IUSR account. Trend Micro has released Critical Patch Build 14136 for on-premises installations and has already mitigated the issue for SaaS customers.

Affected products

  • Trend Micro Apex One 2019 (On-prem) Prior to CP Build 14136
  • Trend Micro Apex One as a Service Prior to Security Agent Build 14.0.20315
  • Trend Micro Trend Vision One Endpoint - Standard Endpoint Protection Prior to Security Agent Build 14.0.20315

Timeline

  • 2025-09-11: disclosed: Vulnerability reported to vendor via Zero Day Initiative
  • 2026-03-03: patched: Coordinated public release of advisory and patches
  • 2026-05-21: advisory: NVD publication date

References

Related threats