CVE-2025-71211Disclosure(trendmicro / apex_one)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch trendmicro apex_one systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability in the Trend Micro Apex One management console could allow a remote attacker to upload malicious code and execute commands on affected installations. This vulnerability is similar in scope to CVE-2025-71210 but affects a different executable. Please note: although this vulnerability carries a technical critical CVSS rating, this was reported via responsible disclosure via a researcher through the Zero Day Initiative. The SaaS versions of the product have already been mitigated and no customer action required. For this particular vulnerability, an attacker must have access to the Trend Micro Apex One Management Console, so customers that have their console�s IP address exposed externally should consider mitigating factors such as source restrictions if not already applied.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • apex_one

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 7 signals
  • Disclosure: 5 classified signals
  • Peaked 2d ago at 3 mentions (2026-02-26); latest day: 1
  • 8 total mentions across 4 days

Affected systems

Vendors
Products
apex_one

Deep dive

Activity timeline8 mentions / 4d
01223Mentions · 2026-02-25: 2Mentions · 2026-02-26: 3Mentions · 2026-03-03: 2Mentions · 2026-03-04: 1Patch / Workaround · 2026-02-25: 1Patch / Workaround · 2026-02-26: 2Technical Details · 2026-02-25: 2Technical Details · 2026-02-26: 3Technical Details · 2026-03-03: 1Technical Details · 2026-03-04: 102-2502-2603-0303-04
Signal classification2 categories
Disclosure
562.5%
Patch
337.5%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-02-252
Disclosure1Patch1
2026-02-263
Disclosure1Patch2
2026-03-032
Disclosure2
2026-03-041
Disclosure1
Full discourse8 posts
  • Autumn Good@autumn_good_35
    Disclosure

    ZDI-CAN-28001 CVE-2025-71210:  Console Directory Traversal Remote Code Execution Vulnerability  ZDI-CAN-28002 CVE-2025-71211:  Console Directory Traversal Remote Code Execution Vulnerability  https://x.com/autumn_good_35/status/2026676902161953231

    Post summary

    Two new CVEs (CVE-2025-71210 and CVE-2025-71211) are disclosed as console directory traversal vulnerabilities that allow remote code execution.

    001111.4K
    6.7K followersView on X
  • Autumn Good@autumn_good_35
    Patch

    🚨🚨🚨 『A vulnerability in the Trend Micro Apex One management console could allow a remote attacker to upload malicious code and execute commands』 CVE-2025-71210、CVE-2025-71211 SECURITY BULLETIN: Apex One and Apex One (Mac) - February 2026 https://success.trendmicro.com/en-US/solution/KA-0022458

    Post summary

    Trend Micro issued a security bulletin for CVE‑2025‑71210 and CVE‑2025‑71211, noting that the Apex One management console could be exploited to upload malicious code and execute commands, and a patch is available via the provided link.

    012001.3K
    6.7K followersView on X
  • CCB Alert@CCBalert
    Disclosure

    Warning: Two critical vulnerabilities in #Trend Micro APEX One. CVE-2025-71210 and CVE-2025-71211 both have a CVSS score of 9.8. Either vulnerability can be exploited to perform remote code execution. #RCE! #Patch #Patch #Patch

    Post summary

    Two newly disclosed critical vulnerabilities (CVE‑2025‑71210 and CVE‑2025‑71211) in Trend Micro APEX One have high CVSS 9.8 scores and allow remote code execution, but no PoC, exploit, or patch details are provided.

    01000273
    7.2K followersView on X
  • TheZDIBugs@TheZDIBugs
    Disclosure

    [ZDI-26-137|CVE-2025-71211] Trend Micro Apex One Console Directory Traversal Remote Code Execution Vulnerability (CVSS 9.8; Credit: Jacky Hsieh and Charles Yang @ CoreCloud Tech.) https://www.zerodayinitiative.com/advisories/ZDI-26-137/

    Post summary

    A new high‑severity CVE‑2025‑71211 affecting Trend Micro Apex One Console has been disclosed, detailing a directory traversal that can lead to remote code execution, with a CVSS score of 9.8.

    00010599
    5.4K followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Trend Micro patches critical Apex One console RCE bugs (CVE-2025-71210/71211) plus multiple local privesc flaws TrendAI (Trend Micro) fixed eight high/critical Apex One issues, including two critical directory-traversal RCE flaws in the on-prem management console (CVE-2025-71210, CVE-2025-71211) that could let remote attackers upload malicious code and execute commands, plus six high-severity local privilege-escalation bugs (CVE-2025-71212 to -71217). Organizations running on-prem Apex One should patch immediately—especially if the console is exposed or reachable from untrusted networks—while SaaS customers were already mitigated. 🎯 Target: Global/Organizations using Trend Micro Apex One (on-prem) #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://www.securityweek.com/trend-micro-patches-critical-apex-one-vulnerabilities/

    Post summary

    Trend Micro released patches for critical Apex One console RCE and local privilege escalation vulnerabilities; organizations should apply the updates immediately.

    0001055
    221 followersView on X
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidades en productos Trend Micro ❗ CVE-2025-71212 ❗ CVE-2025-71211 ❗ CVE-2025-71210 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-trend-micro-2/ https://t.co/zth4dfDLU6

    Post summary

    The post announces three new CVEs affecting Trend Micro products and directs readers to external links for further information.

    00000148
    6.6K followersView on X
  • ねこさん⚡(ΦωΦ)@catnap707
    Disclosure

    "The second, tracked as CVE-2025-71211, is another Apex One management console path traversal vulnerability, similar in scope to CVE-2025-71210 but affecting a different executable." https://x.com/catnap707/status/2027160936449270128?s=20

    Post summary

    The tweet announces a second path traversal vulnerability (CVE‑2025‑71211) in the Apex One management console, noting its similarity to CVE‑2025‑71210 but affecting a different executable.

    00000207
    3.4K followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Trend Micro patches critical Apex One RCE bugs (CVE-2025-71210/71211) — update now Trend Micro fixed two critical directory-traversal RCE flaws in Apex One’s management console (CVE-2025-71210 and CVE-2025-71211, both CVSS 9.8) that could enable malicious code execution if an attacker can reach the console. Apply the Critical Patch Build 14136 and restrict/segment console access (especially if exposed) to reduce exploitation risk. 🎯 Target: Global/Enterprise Endpoints #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://securityaffairs.com/188572/security/trend-micro-fixes-two-critical-flaws-in-apex-one.html

    Post summary

    Trend Micro released critical patches for two RCE vulnerabilities in Apex One, advising users to apply the patch and restrict console access to mitigate risk.

    0000045
    220 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Apptrendmicroapex_one-windows-
Apptrendmicroapex_one-windows-

Explore more