Find notable cyber news and cases, enriched with sources, timelines, and signals.

Trend Micro Apex One management console path traversal RCE (CVE-2025-71210)

Vulnerability
First reported
Last updated
Happening score
H score 11
1 unique sources, 1 articles

Summary

Hide ▲

Trend Micro's Apex One management console flaw CVE-2025-71210 can let attackers without privileges run malicious code on unpatched Windows systems, making it a critical remote code execution risk. The weakness is a path traversal bug in the console component. Trend Micro has already issued fixes, but externally exposed consoles remain the most concerning target until updates are applied.

Timeline

  1. 26.02.2026 19:58 2 articles · 3mo ago

    Trend Micro patches Apex One management console RCE flaws

    Mitigation Patch Update

    Trend Micro patched two critical Apex One management console path traversal vulnerabilities, CVE-2025-71210 and CVE-2025-71211, that can allow attackers with console access to execute malicious code on vulnerable Windows systems. The company also released Critical Patch Build 14136 for SaaS Apex One versions, addressed related high-severity privilege escalation flaws in the Windows and macOS agents, and urged customers to update to the latest builds and restrict externally exposed console access.

    Show sources