Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2025-71210: Trend Micro Apex One Management Console Allows Remote Code Upload

CVE-2025-71210
Summary

A security weakness in the Trend Micro Apex One management console lets hackers upload and run malicious code on affected systems. If your console's IP address is exposed to the internet, consider limiting access to prevent potential attacks. No action is required for SaaS customers, but others should take precautions.

Original title
A vulnerability in the Trend Micro Apex One management console could allow a remote attacker to upload malicious code and execute commands on affected installations. Please note: although this v...
Original description
A vulnerability in the Trend Micro Apex One management console could allow a remote attacker to upload malicious code and execute commands on affected installations.

Please note: although this vulnerability carries a technical critical CVSS rating, this was reported via responsible disclosure via a researcher through the Zero Day Initiative. The SaaS versions of the product have already been mitigated and no customer action required.

For this particular vulnerability, an attacker must have access to the Trend Micro Apex One Management Console, so customers that have their console�s IP address exposed externally should consider mitigating factors such as source restrictions if not already applied.
nvd CVSS3.1 9.8
Vulnerability type
CWE-22 Path Traversal
Published: 21 May 2026 · Updated: 31 May 2026 · First seen: 21 May 2026