CVE-2025-71210Patch(trendmicro / apex_one)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch trendmicro apex_one systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability in the Trend Micro Apex One management console could allow a remote attacker to upload malicious code and execute commands on affected installations. Please note: although this vulnerability carries a technical critical CVSS rating, this was reported via responsible disclosure via a researcher through the Zero Day Initiative. The SaaS versions of the product have already been mitigated and no customer action required. For this particular vulnerability, an attacker must have access to the Trend Micro Apex One Management Console, so customers that have their console�s IP address exposed externally should consider mitigating factors such as source restrictions if not already applied.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • apex_one

Threat summary

  • Patch or workaround signal is available
  • 17 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 11 signals
  • Technical details provided in 13 signals
  • Disclosure: 6 classified signals
  • Peaked 5d ago at 5 mentions (2026-02-26); latest day: 1
  • 17 total mentions across 7 days

Affected systems

Vendors
Products
apex_one

Deep dive

Activity timeline17 mentions / 7d
01345Mentions · 2026-02-25: 2Mentions · 2026-02-26: 5Mentions · 2026-02-27: 4Mentions · 2026-03-03: 2Mentions · 2026-03-04: 2Mentions · 2026-03-05: 1Mentions · 2026-05-27: 1Patch / Workaround · 2026-02-25: 1Patch / Workaround · 2026-02-26: 4Patch / Workaround · 2026-02-27: 4Patch / Workaround · 2026-03-05: 1Patch / Workaround · 2026-05-27: 1Technical Details · 2026-02-25: 2Technical Details · 2026-02-26: 5Technical Details · 2026-02-27: 2Technical Details · 2026-03-03: 1Technical Details · 2026-03-04: 1Technical Details · 2026-03-05: 1Technical Details · 2026-05-27: 102-2502-2602-2703-0303-0403-0505-27
Signal classification2 categories
Patch
1164.7%
Disclosure
635.3%
Referenced assets30 URLs
By indicator
Classification over time
DateTotalLabels
2026-02-252
Disclosure1Patch1
2026-02-265
Disclosure1Patch4
2026-02-274
Patch4
2026-03-032
Disclosure2
2026-03-042
Disclosure2
2026-03-051
Patch1
2026-05-271
Patch1
Full discourse17 posts
  • Autumn Good@autumn_good_35
    Disclosure

    ZDI-CAN-28001 CVE-2025-71210:  Console Directory Traversal Remote Code Execution Vulnerability  ZDI-CAN-28002 CVE-2025-71211:  Console Directory Traversal Remote Code Execution Vulnerability  https://x.com/autumn_good_35/status/2026676902161953231

    Post summary

    Two new CVEs (CVE-2025-71210 and CVE-2025-71211) are disclosed as console directory traversal RCE vulnerabilities, with a tweet link provided but no further details.

    001111.4K
    6.7K followersView on X
  • Autumn Good@autumn_good_35
    Patch

    🚨🚨🚨 『A vulnerability in the Trend Micro Apex One management console could allow a remote attacker to upload malicious code and execute commands』 CVE-2025-71210、CVE-2025-71211 SECURITY BULLETIN: Apex One and Apex One (Mac) - February 2026 https://success.trendmicro.com/en-US/solution/KA-0022458

    Post summary

    Trend Micro issued a security bulletin for CVE-2025-71210 and CVE-2025-71211, warning that the Apex One management console can be exploited to upload malicious code and execute commands, and a patch is available.

    012001.3K
    6.7K followersView on X
  • ねこさん⚡(ΦωΦ)@catnap707
    Patch

    Trend Micro warns of critical Apex One code execution flaws https://www.bleepingcomputer.com/news/security/trend-micro-warns-of-critical-apex-one-rce-vulnerabilities/ "The first critical Apex One security flaw patched this week (CVE-2025-71210) is due to a path traversal weakness in the Trend Micro Apex One management console, allowing attackers without…"

    Post summary

    Trend Micro has released a patch for the CVE‑2025‑71210 path traversal flaw in Apex One, addressing a critical code execution vulnerability.

    10100381
    3.4K followersView on X
  • iototsecnews@iototsecnews
    Patch

    Trend Micro Apex One の脆弱性 CVE-2025-71210/71211 などが FIX:RCE のおそれ https://iototsecnews.jp/2026/02/27/critical-trend-micro-apex-one-vulnerabilities-allow-remote-malicious-code-execution/ Trend Micro の Apex One において、合計で 8 件の脆弱性 CVE-2025-71210~CVE-2025-71217 が修正されました。最も深刻なのは、管理コンソールのディレクトリ・トラバーサルの脆弱性CVE-2025-71210/71211 であり、未認証のリモート攻撃者によるサーバ上での任意のコード実行 (RCE) が可能になります。その他にも、Windows/macOS のエージェントにおけるローカル権限昇格 (LPE) の脆弱性も修正されています。オンプレミス版 (Apex One 2019) を利用している組織は、直ちに Critical Patch Build 14136 を適用する必要があると、同社は指摘しています。SaaS 版の利用者は、エージェントが Build 14.0.20315 以降であることを確認する必要があります。 #ApexOne #CVE202571210 #CVE202571211 #CVE202571212 #CVE202571213 #CVE202571214 #CVE202571215 #CVE202571216 #CVE202571217 #TrendMicro #Vulnerability

    Post summary

    Trend Micro Apex One vulnerabilities CVE‑2025‑71210‑12 through CVE‑2025‑71217 have been fixed; organizations must apply the specified patches to mitigate RCE and LPE risks. No evidence of active exploitation is provided.

    01000188
    483 followersView on X
  • CCB Alert@CCBalert
    Disclosure

    Warning: Two critical vulnerabilities in #Trend Micro APEX One. CVE-2025-71210 and CVE-2025-71211 both have a CVSS score of 9.8. Either vulnerability can be exploited to perform remote code execution. #RCE! #Patch #Patch #Patch

    Post summary

    Two Trend Micro APEX One vulnerabilities (CVE-2025-71210/71211) are highlighted as critical, capable of remote code execution with a CVSS score of 9.8; no PoC, exploit, or patch details are provided.

    01000273
    7.2K followersView on X
  • Machina Record@MachinaRecord
    Patch

    【リンク集:2月26日〜27日のセキュリティ関連ニュース/記事】 <脆弱性> ・Juniper NetworksのPTXシリーズに重大な脆弱性、ルーターの完全な乗っ取りが可能に(CVE-2026-21902) https://www.bleepingcomputer.com/news/security/critical-juniper-networks-ptx-flaw-allows-full-router-takeover/ ・トレンドマイクロ、Apex Oneの重大な脆弱性を修正(CVE-2025-71210、CVE-2025-71211他) https://www.securityweek.com/trend-micro-patches-critical-apex-one-vulnerabilities/ <マルウェア・その他脅威> ・UAT-10027、Dohdoorバックドアで米教育・医療機関を標的に https://thehackernews.com/2026/02/uat-10027-targets-us-education-and.html ・GoogleのパブリックAPIキーからGemini APIのデータにアクセスされる恐れhttps://www.bleepingcomputer.com/news/security/previously-harmless-google-api-keys-now-expose-gemini-ai-data/ <ランサムウェア> ・ランサムウェア攻撃件数が2025年に急増、身代金を支払う被害者は減少 Chainalysis報告 https://therecord.media/ransomware-payments-chainalysis-cybercrime <データ侵害/サイバー犯罪> ・Revolut元従業員が顧客を脅迫か 個人情報の身代金として暗号資産を支払うよう求める https://gizmodo.com/revolut-ex-employee-allegedly-tried-to-extort-a-customer-for-crypto-ransom-2000726288 ・仏サッカークラブのオリンピック・マルセイユ、データリーク経て「未遂」のサイバー攻撃認める https://www.bleepingcomputer.com/news/security/olympique-marseille-football-club-confirms-cyberattack-after-data-leak/ ・欧DIYチェーンManoManoのデータ侵害、顧客3,800万人に影響 https://www.bleepingcomputer.com/news/security/european-dyi-chain-manomano-data-breach-impacts-38-million-customers/ <AI関連> ・ChatGPTが国際的詐欺キャンペーンに悪用される https://www.helpnetsecurity.com/2026/02/26/openai-malicious-chatgpt-use-report/ <逮捕/テイクダウン/制裁/違反/その他法執行関連> ・米ニューヨーク州がValveを訴える ゲームのルートボックス販売がギャンブルを助長したとして https://www.bleepingcomputer.com/news/gaming/new-york-sues-valve-for-promoting-illegal-gambling-via-game-loot-boxes/ ・ギリシャ、Intellexa創設者に拘禁8年の判決 同国の政治家やジャーナリストを盗聴した罪で https://techcrunch.com/2026/02/26/spyware-maker-sentenced-to-prison-in-greece-for-wiretapping-politicians-and-journalists/ ・米空軍元将校が逮捕される ハッカーと共謀し、中国軍に飛行訓練を提供した疑いでhttps://therecord.media/former-air-force-officer-arrested-for-working-with-hacker-flight-training-china <リサーチ/攻撃手法/TTP> ・Cellebriteの2026年業界動向レポート 捜査官の97%がスマホからデジタル証拠を入手 https://www.forensicfocus.com/news/cellebrites-2026-industry-trends-report-reveals-smartphones-as-the-leading-source-of-digital-evidence-in-investigations-at-97/ ・AirSnitch攻撃:家庭・オフィス・企業のWi-Fi暗号化をバイパスする新たな攻撃手法 https://arstechnica.com/security/2026/02/new-airsnitch-attack-breaks-wi-fi-encryption-in-homes-offices-and-enterprises/ ・Aeternum C2ボットネットローダー、暗号化されたコマンドをPolygonブロックチェーンに保存して削除を回避 https://thehackernews.com/2026/02/aeternum-c2-botnet-stores-encrypted.html ・Entra IDでのOAuth同意により、ChatGPTにEメールへのアクセスを許す恐れ https://hackread.com/entra-id-oauth-consent-chatgpt-emails-access/ <政府/政策> ・英政府、脆弱性修正の高速化に向け自動スキャンを導入 長年の課題に対処 https://therecord.media/united-kingdom-vulnerability-scanning-cyber ・AppleのiPhoneとiPad、NATOの情報セキュリティ要件をパス https://www.securityweek.com/apple-iphone-and-ipad-cleared-for-classified-nato-use/

    Post summary

    The post reports a new Juniper PTX series vulnerability allowing full router takeover and notes that Trend Micro has patched its Apex One vulnerabilities.

    00010273
    1.2K followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Trend Micro patches critical Apex One console RCE bugs (CVE-2025-71210/71211) plus multiple local privesc flaws TrendAI (Trend Micro) fixed eight high/critical Apex One issues, including two critical directory-traversal RCE flaws in the on-prem management console (CVE-2025-71210, CVE-2025-71211) that could let remote attackers upload malicious code and execute commands, plus six high-severity local privilege-escalation bugs (CVE-2025-71212 to -71217). Organizations running on-prem Apex One should patch immediately—especially if the console is exposed or reachable from untrusted networks—while SaaS customers were already mitigated. 🎯 Target: Global/Organizations using Trend Micro Apex One (on-prem) #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://www.securityweek.com/trend-micro-patches-critical-apex-one-vulnerabilities/

    Post summary

    Trend Micro released patches for critical Apex One console RCE and local privilege escalation vulnerabilities; organizations should apply the updates immediately.

    0001055
    221 followersView on X
  • Technology Interpreters, Inc.@TechTranslators
    Patch

    Trend Micro Apex One on-prem: two RCEs in the management console, both CVSS 9.8 (CVE-2025-71210/71211). Anyone who reaches the console runs commands. SaaS is patched. If yours is internet-exposed, lock down source IPs. https://nvd.nist.gov/vuln/detail/CVE-2025-71210

    Post summary

    Trend Micro Apex One on‑prem contains two high‑severity RCEs; SaaS has been patched, but on‑prem users should lock down management‑console access.

    0000050
    35 followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    A severe vulnerability was disclosed for Trend Micro Apex One (CVE-2025-71210) https://vuldb.com/?id.348668

    Post summary

    A severe vulnerability (CVE-2025-71210) in Trend Micro Apex One has been disclosed, with details available at the provided link.

    00000145
    2.1K followersView on X
  • TheZDIBugs@TheZDIBugs
    Disclosure

    [ZDI-26-136|CVE-2025-71210] Trend Micro Apex One Console Directory Traversal Remote Code Execution Vulnerability (CVSS 9.8; Credit: Jacky Hsieh and Charles Yang @ CoreCloud Tech.) https://www.zerodayinitiative.com/advisories/ZDI-26-136/

    Post summary

    An advisory announces CVE-2025-71210, a high‑severity directory traversal RCE vulnerability in Trend Micro Apex One Console, with a CVSS score of 9.8.

    00000524
    5.4K followersView on X
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidades en productos Trend Micro ❗ CVE-2025-71212 ❗ CVE-2025-71211 ❗ CVE-2025-71210 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-trend-micro-2/ https://t.co/zth4dfDLU6

    Post summary

    The post announces three new CVEs (CVE‑2025‑71212, CVE‑2025‑71211, CVE‑2025‑71210) affecting Trend Micro products and provides a link for additional information.

    00000148
    6.6K followersView on X
  • サイバーセキュリティニュース-JP@cybersecnews_jp
    Patch

    トレンドマイクロ Apex Oneに複数の脆弱性を修正(CVE-2025-71210〜71217) https://rocket-boys.co.jp/security-measures-lab/trend-micro-apex-one-multiple-vulnerabilities-fixed-cve-2025-71210-71217/

    Post summary

    Trend Micro Apex One has released fixes for CVE-2025-71210 through CVE-2025-71217, as noted in the article.

    00000149
    43 followersView on X
  • SempreUpdate@SempreUpdate
    Patch

    Falhas críticas de RCE no Trend Micro Apex One exigem atualização urgente https://sempreupdate.com.br/trend-micro-apex-one-falhas-rce-cve-2025-71210-71211/

    Post summary

    The text announces that Trend Micro Apex One has critical remote code execution vulnerabilities (CVE‑2025‑71210, CVE‑2025‑71211) and urges users to apply urgent updates.

    0000055
    4.7K followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Patch

    トレンドマイクロ Apex Oneに複数の脆弱性を修正(CVE-2025-71210〜71217) https://rocket-boys.co.jp/security-measures-lab/trend-micro-apex-one-multiple-vulnerabilities-fixed-cve-2025-71210-71217/ #セキュリティ対策Lab #セキュリティ #Security #CybersecurityNews

    Post summary

    Trend Micro Apex One has addressed a series of vulnerabilities (CVE-2025-71210 through 71217) with patches, and the text provides no evidence of active exploitation, PoC, or exploit tools.

    00000153
    320 followersView on X
  • ねこさん⚡(ΦωΦ)@catnap707
    Disclosure

    "The second, tracked as CVE-2025-71211, is another Apex One management console path traversal vulnerability, similar in scope to CVE-2025-71210 but affecting a different executable." https://x.com/catnap707/status/2027160936449270128?s=20

    Post summary

    A second path traversal vulnerability (CVE-2025-71211) in the Apex One management console is disclosed, similar to CVE-2025-71210 but targeting a different executable.

    00000207
    3.4K followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Trend Micro patches critical Apex One RCE bugs (CVE-2025-71210/71211) — update now Trend Micro fixed two critical directory-traversal RCE flaws in Apex One’s management console (CVE-2025-71210 and CVE-2025-71211, both CVSS 9.8) that could enable malicious code execution if an attacker can reach the console. Apply the Critical Patch Build 14136 and restrict/segment console access (especially if exposed) to reduce exploitation risk. 🎯 Target: Global/Enterprise Endpoints #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://securityaffairs.com/188572/security/trend-micro-fixes-two-critical-flaws-in-apex-one.html

    Post summary

    Trend Micro released critical patches for two Apex One RCE vulnerabilities (CVE‑2025‑71210/71211) with CVSS 9.8, advising users to apply Patch Build 14136 and restrict console access.

    0000045
    220 followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Trend Micro Patches Critical Apex One Console Path Traversal Bugs Enabling RCE (CVE-2025-71210/71211) Trend Micro fixed two critical path traversal flaws in the Apex One management console that can let attackers with access to the console execute malicious code on unpatched Windows deployments; SaaS instances were patched and on-prem customers should update to Critical Patch Build 14136 and restrict console exposure/IP access immediately. 🎯 Target: Global/Enterprise Endpoint Security #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://www.bleepingcomputer.com/news/security/trend-micro-warns-of-critical-apex-one-rce-vulnerabilities/

    Post summary

    Trend Micro released critical patches for Apex One console path traversal vulnerabilities (CVE‑2025‑71210/71211) that could allow remote code execution; on‑prem customers are advised to apply Critical Patch Build 14136 and restrict console exposure/IP access.

    0000035
    220 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Apptrendmicroapex_one-windows-
Apptrendmicroapex_one-windows-

Explore more