CVE-2025-54948: Trend Micro Apex One OS Command Injection Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2025-08-18. EPSS: 23.9% chance of exploitation in the next 30 days.

A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious code and execute commands on affected installations.

Affected products

Published 2025-08-05. Last modified 2026-06-17.