CVE-2025-71210
CVE-2025-71210 is a critical-severity vulnerability in Trendmicro Apex One with a CVSS 3.x base score of 9.8. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-22.
Key facts
- Severity: Critical (CVSS 3.x base score 9.8)
- EPSS exploit prediction: 4% (89th percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2025-209909
- Weakness: CWE-22
- Affected product: Trendmicro Apex One
- Published:
- Last modified:
Description
A vulnerability in the Trend Micro Apex One management console could allow a remote attacker to upload malicious code and execute commands on affected installations. Please note: although this vulnerability carries a technical critical CVSS rating, this was reported via responsible disclosure via a researcher through the Zero Day Initiative. The SaaS versions of the product have already been mitigated and no customer action required. For this particular vulnerability, an attacker must have access to the Trend Micro Apex One Management Console, so customers that have their console�s IP address exposed externally should consider mitigating factors such as source restrictions if not already applied.
Frequently asked questions
- What is CVE-2025-71210?
- A vulnerability in the Trend Micro Apex One management console could allow a remote attacker to upload malicious code and execute commands on affected installations. Please note: although this vulnerability carries a technical critical CVSS rating, this was reported via responsible disclosure via a researcher through the Zero Day Initiative. The SaaS versions of the product have already been mitigated and no customer action required. For this particular vulnerability, an attacker must have access to the Trend Micro Apex One Management Console, so customers that have their console�s IP address exposed externally should consider mitigating factors such as source restrictions if not already applied.
- How severe is CVE-2025-71210?
- CVE-2025-71210 has a CVSS 3.x base score of 9.8, rated critical severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability high.
- Is CVE-2025-71210 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 4% (89th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2025-71210?
- CVE-2025-71210 primarily affects Trendmicro Apex One. In total, 2 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2025-71210?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its critical severity, prioritise patching exposed systems.
- Does CVE-2025-71210 have an EU (EUVD) identifier?
- Yes. CVE-2025-71210 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2025-209909.
- When was CVE-2025-71210 published?
- CVE-2025-71210 was published on 2026-05-21 and last updated on 2026-07-23.
References
- https://success.trendmicro.com/en-US/solution/KA-0022458
- https://www.zerodayinitiative.com/advisories/ZDI-26-136/
Affected products (2)
- cpe:2.3:a:trendmicro:apex_one:*:*:*:*:on-premises:windows:*:*
- cpe:2.3:a:trendmicro:apex_one:*:*:*:*:saas:windows:*:*
More vulnerabilities in Trendmicro Apex One
- CVE-2025-71211 — Critical (CVSS 9.8): A vulnerability in the Trend Micro Apex One management console could allow a remote attacker to upload malicious code…
- CVE-2023-32557 — Critical (CVSS 9.8): A path traversal vulnerability in the Trend Micro Apex One and Apex One as a Service could allow an unauthenticated…
- CVE-2023-25143 — Critical (CVSS 9.8): An uncontrolled search path element vulnerability in the Trend Micro Apex One Server installer could allow an attacker…
- CVE-2022-40144 — Critical (CVSS 9.8): A vulnerability in Trend Micro Apex One and Trend Micro Apex One as a Service could allow an attacker to bypass the…
- CVE-2022-26871 — Critical (CVSS 9.8): An arbitrary file upload vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to…
- CVE-2020-8599 — Critical (CVSS 9.8): Trend Micro Apex One (2019) and OfficeScan XG server contain a vulnerable EXE file that could allow a remote attacker…
All CVEs affecting Trendmicro Apex One →
Other CWE-22 (Path Traversal) vulnerabilities
- CVE-2026-76606 — Critical (CVSS 10.0): Joomla Extension - fabrikar.com - Path Traversal via image element in Fabrik < 4.7.3 - ???.
- CVE-2026-18051 — Critical (CVSS 10.0): The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the request path it uses to build cache…
- CVE-2026-74764 — Critical (CVSS 10.0): Pandora contains a path traversal vulnerability in its TAR archive extraction functionality. When processing a…
- CVE-2026-16940 — Critical (CVSS 10.0): The Custom Fields WordPress plugin before 1.5.1 does not validate a user-supplied file path before deletion, allowing…
- CVE-2026-67429 — Critical (CVSS 10.0): Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, image.download and related…
- CVE-2026-59555 — Critical (CVSS 10.0): Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.3 versions.