ZeroHour
Infosecurity Magazinepublished ()ingested James Coker

Attackers Are Targeting Critical Apex One Vulnerabilities, Trend Micro

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-54948
Pre-auth OS command injection in Trend Micro Apex One on-prem Management Console

Trend Micro Apex One's on-premises Management Console contains an OS command injection flaw (CWE-78) that a remote attacker can reach prior to authentication. By sending crafted requests to the console, the attacker can inject arbitrary OS commands and upload malicious code to the server hosting the console. Successful exploitation yields remote code execution on the Apex One management server, which typically holds privileged network access and controls the managed endpoint fleet. Only organizations running the on-premise Apex One Management Console are affected; the source data does not enumerate specific vulnerable builds. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-08-18, confirming active exploitation in the wild, though no public proof-of-concept is known and ransomware involvement is not yet confirmed.

Do: Apply Trend Micro's patched builds or vendor-directed mitigations for the on-prem Apex One Management Console immediately, per the CISA KEV required action and BOD 22-01 guidance (federal agencies face a KEV deadline). Restrict the Management Console from direct internet exposure via firewall or VPN, and hunt the management server for signs of compromise such as unexpected uploaded files or processes, since active exploitation is confirmed. Ransomware association is unconfirmed but should be assumed possible until vendor guidance says otherwise.

9.822% KEV
  • Trend Micro Apex One (on-premises Management Console)
large≈ tens of thousands of on-prem Management Console deployments (estimate; no published install counts in source data)
CVE-2025-54987
A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious code and execute com

A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious code and execute commands on affected installations. This vulnerability is essentially the same as CVE-2025-54948 but targets a different CPU architecture.

NVD description · AI analysis pending
9.817%
  • trendmicro apex one
Full article354 words · extracted from infosecurity-magazine.com · click to collapse

Cybersecurity firm Trend Micro has warned customers that attackers are actively targeting critical vulnerabilities in on-premises Apex One Management Consoles.

The vulnerabilities, CVE-2025-54948 and CVE-2025-54987, were disclosed in a critical security bulletin on August 5. They impact Trend Micro Apex One (on-prem) machines Management Server Version 14039 and below.

The remote code execution (RCE) flaws can enable a pre-authenticated attacker to upload malicious code and execute commands on affected installations.

The two vulnerabilities are essentially the same but target a different CPU architecture on Apex One, Trend Micro wrote.

Both vulnerabilities have been given a critical CVE rating of 9.4.

“Trend Micro has observed as least one instance of an attempt to actively exploit one of these vulnerabilities in the wild,” the company warned.

Temporary Fix Available, Formal Patch to Follow

Trend Micro has released a mitigation tool to enable customers to protect against exploitation.

However, this is only a short-term fix. A more formal critical patch for Apex One is expected to be released around mid-August 2025.

“The fix tool listed in this bulletin is a short-term mitigation, and while it will fully protect against known exploits, it will disable the ability for administrators to utilize the Remote Install Agent function to deploy agents from the Trend Micro Apex One Management Console,” the company noted.

Trend Micro also notified customers that a key backend certificate in Apex One will be updated near the end of September 2025. As a result, several on-premise products will need to be at a minimum version to prevent issues with updates.

As exploitation of the two vulnerabilities generally requires an attacker to gain physical or remote access to a vulnerable machine, Trend Micro advised customers to undertake additional mitigation measures alongside applying the temporary fix.

  • Review remote access to critical systems
  • Ensure policies and perimeter security is up to date
  • Customers that have their console’s IP address exposed externally should consider mitigation factors such as source restrictions

Trend Micro acknowledged the work of its incident response team and Jacky Hsieh, senior researcher at CoreCloud Tech, for discovering and responsibly disclosing the vulnerabilities.

Image credit: photo_gonzo / Shutterstock.com

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/attackers-critical-apex-one/