ZDI-CAN-27976: ZDI-26-270: TrendAI Apex One Console Directory Traversal Remote Code Execution Vulnerability
Published Apr 15, 2026
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Trend Micro Apex One. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2025-54987.
Affected Software
1 affected component
Trend Micro Apex One Console
Event History
Apr 15, 2026
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-27976?
ZDI-CAN-27976 has a CVSS rating of 9.8, indicating it is a critical vulnerability.
2
What does ZDI-CAN-27976 allow attackers to do?
ZDI-CAN-27976 allows remote attackers to execute arbitrary code on affected installations of Trend Micro Apex One.
3
Is authentication required to exploit ZDI-CAN-27976?
No, authentication is not required to exploit ZDI-CAN-27976.
4
How do I fix ZDI-CAN-27976?
To fix ZDI-CAN-27976, update your Trend Micro Apex One Console to the latest version provided by Trend Micro.
5
What software does ZDI-CAN-27976 affect?
ZDI-CAN-27976 affects Trend Micro Apex One Console installations.