To fix serious security holes in on-premise versions of Apex One Management Console that have reportedly been exploited in the wild, Trend Micro has published mitigations.
Both CVE-2025-54948 and CVE-2025-54987, which received a score of 9.4 on the CVSS scoring system, have been identified as remote code execution and management console command injection vulnerabilities.
According to a Tuesday alert from the cybersecurity firm, a pre-authenticated remote attacker may be able to upload malicious code and run commands on compromised installations due to a flaw in Trend Micro’s Apex One (on-premise) management dashboard.
Although the two flaws are nearly identical, CVE-2025-54987 focuses on a distinct CPU architecture. The two vulnerabilities were reported by Jacky Hsieh of CoreCloud Tech and the Trend Micro Incident Response (IR) Team.
As of right now, no information is available regarding how the vulnerabilities are being used in actual assaults read more about Trend Micro Confirms Active Exploitation of Critical Apex One Flaws in On-Premise Systems.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
