PT-2026-21991 · Trend Micro · Trend Micro Apex One

Published

2025-09-11

·

Updated

2026-05-27

·

CVE-2025-71210

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Trend Micro Apex One (affected versions not specified)
Description The Trend Micro Apex One management console contains a path traversal weakness. This allows attackers with access to the console to execute malicious code on unpatched Windows deployments. The issue is a directory traversal that can lead to remote code execution. The flaw affects global and enterprise endpoint security systems.
Recommendations Update to Critical Patch Build 14136. Restrict console exposure and IP access.

Fix

RCE

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2026-07811
CVE-2025-71210
ZDI-26-136

Affected Products

Trend Micro Apex One