Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Critical Trend Micro Apex One Vulnerabilities Allow Remote Malicious Code Execution

Trend Micro has identified eight security vulnerabilities in its Apex One endpoint protection platform, including two critical-severity flaws that permit unauthenticated remote attackers to upload malicious code and execute commands on affected systems.

Trend Micro has identified eight security vulnerabilities in its Apex One endpoint protection platform, including two critical-severity flaws that permit unauthenticated remote attackers to upload malicious code and execute commands on affected systems.

A Critical Patch was released on February 24, 2026, under Solution ID KA-0022458, applicable to Apex One 2019 (on-premises) for Windows and macOS platforms.

The security bulletin from February 2026 highlights eight CVEs, CVE-2025-71210 through CVE-2025-71217, with CVSS 3.1 scores ranging from 7.2 to 9.8.

The two most severe vulnerabilities, rated Critical (CVSS 9.8), are located in the Apex One management console and exploit directory traversal weaknesses, allowing remote code execution without authentication.

The remaining six vulnerabilities are rated High (CVSS 7.2–7.8) and enable local privilege escalation on both Windows and macOS systems.

CVE ID Title CVSS Weakness Platform Impact

CVE-2025-71210 Console Directory Traversal RCE 9.8 CWE-22 Windows Remote code execution via malicious upload

CVE-2025-71211 Console Directory Traversal RCE 9.8 CWE-22 Windows Remote code execution; affects different executable than CVE-2025-71210

CVE-2025-71212 Scan Engine Link Following LPE 7.8 CWE-59 Windows Local privilege escalation via scan engine

The security bulletin from February 2026 highlights eight CVEs, CVE-2025-71210 through CVE-2025-71217, with CVSS 3.1 scores ranging from 7.2 to 9.8.
Brian Shaw · Thehackingpost

CVE-2025-71213 Origin Validation Error LPE 7.8 CWE-346 Windows Local privilege escalation via origin validation flaw

CVE-2025-71214 Agent iCore Service Origin Validation LPE 7.2 CWE-346 macOS Local privilege escalation in iCore service

CVE-2025-71215 Agent iCore TOCTOU Signature Verification LPE 7.8 CWE-367 macOS Local privilege escalation via time-of-check/time-of-use race condition

CVE-2025-71216 Agent Cache Mechanism TOCTOU LPE 7.8 CWE-367 macOS Local privilege escalation via cache mechanism race condition

CVE-2025-71217 Agent Self-Protection Origin Validation LPE 7.8 CWE-346 macOS Local privilege escalation in self-protection module

CVE-2025-71210 and CVE-2025-71211 are the most critical flaws identified. Both exploit improper handling of directory traversal sequences in the Apex One management console, enabling a remote, non-authenticated attacker to send a specially crafted HTTP request to upload and execute arbitrary code. While the CVEs differ in the specific executable they target, both carry identical attack vectors: network-accessible, no authentication required, no user interaction needed.

Advertisement

The four Windows local privilege escalation flaws, CVE-2025-71212 and CVE-2025-71213, require low-privileged code execution access before exploitation. The four macOS vulnerabilities (CVE-2025-71214 through CVE-2025-71217) were mitigated via ActiveUpdate and SaaS releases in mid-to-late 2025.

Product Affected Version Platform Fix

Apex One 2019 (On-premises) Windows CP Build 14136

Apex One as a Service SaaS Windows Security Agent Build 14.0.20315

Trend Vision One Endpoint – Standard Endpoint Protection SaaS Windows Security Agent Build 14.0.20315

Apex One (Mac) All versions macOS Already mitigated via SaaS 2507 & 2005 Yearly Release

Apply CP Build 14136 for Apex One 2019 (on-premises) immediately from Trend Micro's Download Center. Upgrade Apex One as a Service agents to Security Agent Build 14.0.20315. Restrict external IP access to the Apex One management console to minimize exposure for CVE-2025-71210 and CVE-2025-71211. Enforce source IP restrictions on the management console if it is externally accessible. Review all remote access policies to critical security infrastructure and ensure perimeter security is current.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories