ZeroHour
Story · 1 source · 3 articlesfirst updated ()

Zero Day Initiative publishes three Trend Micro Apex One local privilege escalation advisories (ZDI-26-652, ZDI-26-653, ZDI-26-654)

What's new: Initial merge: this is the first consolidated summary for the story, combining three ZDI advisories (ZDI-26-652, ZDI-26-653, ZDI-26-654) published the same day into a single dashboard entry; no prior summary existed.
Merged summary · glm-5.3-flash · rewritten as coverage arrives

ZDI published three advisories dated 2026-09-10 for local privilege escalation flaws in Trend Micro Apex One Security Agent: two TOCTOU race conditions in the cache mechanism (CVE-2025-71415, CVE-2025-71416) and one incomplete cleanup flaw (CVE-2025-71414),…

The Zero Day Initiative published three coordinated advisories covering local privilege escalation vulnerabilities in the Trend Micro Apex One Security Agent. ZDI-26-652 (CVE-2025-71416) and ZDI-26-653 (CVE-2025-71415) describe time-of-check time-of-use (TOCTOU) flaws in the Apex One cache mechanism, while ZDI-26-654 (CVE-2025-71414) covers an incomplete cleanup flaw. All three allow local attackers to escalate privileges after gaining low-privileged code execution, and ZDI rated all three CVSS 7.8. Vendor fixes/patches are available for affected installations. The three reports are consistent; no source disagreements were found.

  • ZDI-26-652: TOCTOU flaw in the Apex One Security Agent cache mechanism, tracked as CVE-2025-71416, CVSS 7.8
  • ZDI-26-653: TOCTOU flaw in the Apex One Security Agent cache mechanism, tracked as CVE-2025-71415, CVSS 7.8
  • ZDI-26-654: Incomplete cleanup flaw in Trend Micro Apex One, tracked as CVE-2025-71414, CVSS 7.8
  • All three flaws allow local privilege escalation and require prior low-privileged code execution
  • Vendor fixes/patches are available for affected installations
  • Disclosure was coordinated by the Zero Day Initiative, with the advisories published per reports dated 2026-09-10
ProductsApex One
OrganizationsZero Day Initiative

Coverage timeline

  1. · 5d ago
    ZDI Published Advisories· 25
    ZDI-26-654: TrendAI Apex One Incomplete Cleanup Local Privilege Escalation Vulnerability

    ZDI-26-654: Trend Micro Apex One incomplete cleanup flaw, CVE-2025-71414, enables local privilege escalation, rated CVSS 7.8.

  2. · 5d ago
    ZDI Published Advisories· 25
    ZDI-26-652: TrendAI Apex One Security Agent Cache Mechanism Time-Of-Check Time-Of-Use Local Privilege Escalation Vulnerability

    ZDI-26-652: TOCTOU race in Trend Micro Apex One cache mechanism, CVE-2025-71416, enables local privilege escalation, rated CVSS 7.8.

  3. · 5d ago
    ZDI Published Advisories· 25
    ZDI-26-653: TrendAI Apex One Security Agent Cache Mechanism Time-Of-Check Time-Of-Use Local Privilege Escalation Vulnerability

    ZDI-26-653: TOCTOU race in Trend Micro Apex One cache mechanism, CVE-2025-71415, enables local privilege escalation, rated CVSS 7.8.

Vulnerabilities in this storyAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-71414

NVD description · AI analysis pending
CVE-2025-71415

NVD description · AI analysis pending
CVE-2025-71416

NVD description · AI analysis pending