Japanese cybersecurity software firm Trend Micro has patched two critical Apex One vulnerabilities that allow attackers to gain remote code execution (RCE) on vulnerable Windows systems. Apex One is an endpoint security platform that detects and responds to security threats, including malware, spyware, malicious tools, and vulnerabilities. The first critical Apex One security flaw patched this week (CVE-2025-71210) is due to a path traversal weakness in the Trend Micro Apex One management console, allowing attackers without privileges to execute malicious code on unpatched systems. The second, tracked as CVE-2025-71211, is another Apex One management console path traversal vulnerability, similar in scope to CVE-2025-71210 but affecting a different executable. As Trend Micro explained in a Tuesday security advisory, successful exploitation requires attackers to "have access to the Trend Micro Apex One Management Console, so customers that have their console's IP address exposed externally should consider mitigating factors such as source restrictions if not already applied." "Even though an exploit may require several specific conditions to be met, Trend Micro strongly encourages customers to update to the latest builds as soon as possible," it warned. To address these critical security flaws, Trend Micro has patched the vulnerabilities in the SaaS Apex One versions and released Critical Patch Build 14136, which also fixes two high-severity privilege escalation flaws in the W...
Trend Micro warns of critical Apex One code execution flaws
BleepingComputer
·Sergiu Gatlan
·Published Feb 26, 2026
·Updated
Affected Software
1 affected component
Trend Micro Apex One<=Critical Patch Build 14136
Frequently Asked Questions
1
What vulnerabilities does the article discuss?
The article discusses two critical remote code execution vulnerabilities in Trend Micro's Apex One software.
2
What is the impact of these vulnerabilities?
These vulnerabilities allow attackers to gain remote code execution on vulnerable Windows systems.
3
Which product is affected by the vulnerabilities mentioned in the article?
The affected product is Trend Micro Apex One, up to and including Critical Patch Build 14136.
4
Who is the vendor of the software affected by these vulnerabilities?
The vendor of the affected software is Trend Micro, a Japanese cybersecurity firm.
5
What action has Trend Micro taken regarding these vulnerabilities?
Trend Micro has issued patches to address the critical vulnerabilities in Apex One.