Attackers Exploit Critical Trend Micro Apex One Zero-Day Flaw
ID: 54a7e123-39d4-5317-8669-b51b24b59a1e
STIX ID: report--54a7e123-39d4-5317-8669-b51b24b59a1e
Feed Name: Dark Reading
Date Published: 2025-08-06
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
Trend Micro disclosed two critical zero-day command-injection vulnerabilities (CVE-2025-54948 and CVE-2025-54987) in the Apex One Management Console for Windows that can lead to remote code execution and full control of enterprise security infrastructure; at least one exploitation attempt has been observed in the wild, cloud services have been patched, and on-premise fixes and mitigations are being released.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
