ZDI-CAN-26597: ZDI-26-146: Trend Micro Apex Central Manual Update Server-Side Request Forgery Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Trend Micro Apex Central. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 4.4. The following CVEs are assigned: CVE-2025-71207.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-26597?
The severity of ZDI-CAN-26597 is significant due to the potential for information disclosure on affected installations.
How do I fix ZDI-CAN-26597?
To fix ZDI-CAN-26597, apply the latest security patches provided by Trend Micro for Apex Central.
What types of sensitive information can be disclosed by ZDI-CAN-26597?
ZDI-CAN-26597 may allow remote attackers to disclose sensitive configuration data or user credentials from Apex Central.
Is authentication required to exploit ZDI-CAN-26597?
Yes, authentication is required to exploit ZDI-CAN-26597, limiting the attack surface to authenticated users.
What versions of Trend Micro Apex Central are affected by ZDI-CAN-26597?
ZDI-CAN-26597 affects all versions of Trend Micro Apex Central that are not patched against this vulnerability.