ZDI-CAN-26037: ZDI-26-147: Trend Micro Apex Central Improper Authentication Privilege Escalation Vulnerability
Published Mar 3, 2026
·Updated
This vulnerability allows remote attackers to escalate privileges on affected installations of Trend Micro Apex Central. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.1. The following CVEs are assigned: CVE-2025-71208.
Affected Software
1 affected component
Trend Micro Apex Central
Event History
Mar 3, 2026
Advisory Published
via ZDI·06:00 AM
Data Sourced
via ZDI·06:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-26037?
ZDI-CAN-26037 is classified as a high severity vulnerability affecting Trend Micro Apex Central.
2
How do I fix ZDI-CAN-26037?
To fix ZDI-CAN-26037, apply the latest security patches released by Trend Micro for Apex Central.
3
What type of vulnerability is ZDI-CAN-26037?
ZDI-CAN-26037 is an improper authentication vulnerability that allows for privilege escalation.
4
Who is affected by ZDI-CAN-26037?
ZDI-CAN-26037 affects installations of Trend Micro Apex Central that have not been updated.
5
Is authentication required to exploit ZDI-CAN-26037?
Yes, authentication is required to exploit ZDI-CAN-26037.