CVE-2025-49216: Trend Micro Endpoint Encryption

Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.

An authentication bypass vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to access key methods as an admin user and modify product configurations on affected installations.

Affected products

  • Trend Micro Trend Micro Endpoint Encryption: before 6.0.0.4013 (fixed in 6.0.0.4013)

Published 2025-06-17. Last modified 2026-06-17.