Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Endpoint Security

Trend Micro Patches Critical Apex One Vulnerabilities

TrendAI has fixed eight critical and high-severity issues in Windows and macOS endpoint security products.

Trend Micro vulnerability

TrendAI, the new name of Trend Micro’s enterprise business, on Wednesday announced patches for several critical and high-severity vulnerabilities found in the Windows and macOS versions of the Apex One endpoint security solution.

A total of eight vulnerabilities have been addressed, including two with a critical severity rating based on their CVSS scores.

The critical flaws both impact the Trend Micro Apex One management console and “could allow a remote attacker to upload malicious code and execute commands on affected installations”.

These security holes, tracked as CVE-2025-71210 and CVE-2025-71211, are similar in scope, but they impact different executables, the cybersecurity firm noted in its advisory.

The remaining vulnerabilities — all assigned a high severity rating — can be exploited by an attacker who already has access to the targeted system to escalate privileges. 

The high-severity issues have been assigned the CVE identifiers CVE-2025-71212 through CVE-2025-71217.

Advertisement. Scroll to continue reading.

“Exploiting these type of vulnerabilities generally require that an attacker has access (physical or remote) to a vulnerable machine. In addition to timely application of patches and updated solutions, customers are also advised to review remote access to critical systems and ensure policies and perimeter security is up-to-date,” TrendAI explained.

All of the vulnerabilities were reported to TrendAI through the Zero Day Initiative (ZDI). Patches are available for the on-premises versions; users of SaaS versions of Apex One do not need to take any action.

TrendAI is not aware of in-the-wild exploitation, but it’s not uncommon for threat actors to exploit vulnerabilities in Apex products. 

CISA’s Known Exploited Vulnerabilities (KEV) catalog currently includes 10 CVEs associated with flaws affecting Apex products.

Attribution information is rarely made public, but some attacks have been linked to Chinese hackers.

Related: Trend Micro Patches Critical Code Execution Flaw in Apex Central

Related: Taiwan Security Firm Confirms Flaw Flagged by CISA Likely Exploited by Chinese APTs

Related: Critical Vulnerabilities Patched in Trend Micro Apex Central, Endpoint Encryption     

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Delve into big-picture strategies to reduce attack surfaces, improve patch management, conduct post-incident forensics, and tools and tricks needed in a modern organization.

Register

Organizations are investing heavily in third-party risk management, but breaches, delays, and blind spots continue to persist. Join this live webinar as we examine the gap between how organizations think their third-party risk programs are performing and what’s actually happening in practice.

Register

People on the Move

Joe Chen has become Chief Technology Officer at Trellix.

Usercentrics has named Pawan Hegde as COO and Elena Ignatova as CPTO.

SecureAuth has named Mark van Oppen as Chief Revenue Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.