Trend Micro Confirms Active Exploitation of Critical Apex One Flaws in On-Premise Systems
To fix serious security holes in on-premise versions of Apex One Management Console that have reportedly been exploited in the wild, Trend Micro has published mitigations.
Both CVE-2025-54948 and CVE-2025-54987, which received a score of 9.4 on the CVSS scoring system, have been identified as remote code execution and management console command injection vulnerabilities.
According to a Tuesday alert from the cybersecurity firm, a pre-authenticated remote attacker may be able to upload malicious code and run commands on compromised installations due to a flaw in Trend Micro's Apex One (on-premise) management dashboard.
Although the two flaws are nearly identical, CVE-2025-54987 focuses on a distinct CPU architecture. The two vulnerabilities were reported by Jacky Hsieh of CoreClou...

