CVE-2025-54948: Trend Micro Apex One OS Command Injection Vulnerability
Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2025-08-18. EPSS: 23.9% chance of exploitation in the next 30 days.
A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious code and execute commands on affected installations.
Affected products
- Trend Micro Apex One: version 2019 only
Published 2025-08-05. Last modified 2026-06-17.