Trend Micro Patches Critical Apex One Vulnerabilities Exploited in Real World.

 Trend Micro has rolled out mitigations and plans a full patch by mid-August for critical flaws in multiple Apex One versions. These vulnerabilities permit command injection and remote code execution via the Management Console. Exploits have already surfaced, raising alarms about potential active attacks

The two high-severity bugs, tracked as CVE‑2025‑54948 and CVE‑2025‑54987, each carry a CVSS score of 9.4. Both impact on-premise Apex One Management Console installations. Trend Micro provided a temporary remediation tool to assist organizations in protecting their systems immediately

Organizations still using vulnerable versions should deploy the mitigation tool without delay. The tool disables the use of the Remote Install Agent function in the Management Console. However, alternative deployment methods—including UNC path or agent package delivery—remain functional.

These vulnerabilities represent a serious risk for enterprises managing endpoint security with Apex One. Attackers could exploit this weakness to execute unauthorized code and gain control over critical infrastructure. The timely patch release highlights the importance of maintaining proactive risk management and compliance practices.

This incident underscores that established security solutions are not immune to threats themselves. It reinforces the critical need for integrated vulnerability management, proactive detection, and GRC frameworks focused on cybersecurity resilience. Organizations are strongly advised to act now to avoid compromise.

 

Must Read

Malwarebytes Award MRG Effitas Names Winner.

Malwarebytes Award Marks Industry Recognition for ThreatDown Endpoint Protection Malwarebytes...

Agentic Endpoint Integration Expands at Palo Alto.

Agentic Endpoint Integration Surge Palo Alto Networks has introduced a...

Lookout Security Unveils Unique Endpoint to Cloud Platform.

Lookout Security Introduces a Unified Cloud Security Platform Lookout, Inc....

KasperskyOS Launch A Next-Gen Secure OS by Kaspersky.

KasperskyOS Launch Expands Beyond Endpoint Protection Kaspersky Lab made headlines...

Trellix Security Leads in IDC MarketScape Report.

Trellix Security Recognized in IDC MarketScape Assessment Trellix has recently...

Topics

Malwarebytes Award MRG Effitas Names Winner.

Malwarebytes Award Marks Industry Recognition for ThreatDown Endpoint Protection Malwarebytes...

Agentic Endpoint Integration Expands at Palo Alto.

Agentic Endpoint Integration Surge Palo Alto Networks has introduced a...

Lookout Security Unveils Unique Endpoint to Cloud Platform.

Lookout Security Introduces a Unified Cloud Security Platform Lookout, Inc....

KasperskyOS Launch A Next-Gen Secure OS by Kaspersky.

KasperskyOS Launch Expands Beyond Endpoint Protection Kaspersky Lab made headlines...

Trellix Security Leads in IDC MarketScape Report.

Trellix Security Recognized in IDC MarketScape Assessment Trellix has recently...

Palo Alto Networks Pursues $400 Million Koi Security.

Palo Alto Acquisition Strategy in Endpoint Security Palo Alto Networks...

McAfee Rebranding Signals Global Endpoint Security Shift.

McAfee Rebranding Drives Global Endpoint Security Transformation McAfee, a long-established...

Symantec AI-Powered Endpoint Security Platform.

Symantec Introduces AI-Driven Endpoint Security Innovation Symantec, a global cybersecurity...

Related Articles

Popular Tags