ZDI-26-269: TrendAI Apex One Console Directory Traversal Remote Code Execution Vulnerability
Published Apr 15, 2026
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Trend Micro Apex One. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2025-54948.
Affected Software
1 affected component
Trend Micro Apex One
Event History
Apr 15, 2026
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-26-269?
ZDI-26-269 has a high severity rating due to its potential for remote code execution without authentication.
2
How do I fix ZDI-26-269?
To fix ZDI-26-269, apply the security patches provided by Trend Micro for Apex One.
3
What impact does ZDI-26-269 have on my system?
ZDI-26-269 can allow unauthorized remote attackers to execute arbitrary code on affected systems.
4
Is authentication required to exploit ZDI-26-269?
No, authentication is not required to exploit the ZDI-26-269 vulnerability.
5
Which software is affected by ZDI-26-269?
The vulnerability ZDI-26-269 affects Trend Micro Apex One installations.