Trend Micro Apex One Vulnerabilities Allow Remote Code Execution

Trend Micro Apex One Vulnerabilities Allow Remote Code Execution

First seen 26 Feb 2026, 18:12 UTC Heise.DeSecurityweekBleepingcomputerRescanaSecurityaffairs.Co+8 86% similarity 52.2

Article Content

Browse articles
ThreatCluster

Trend Micro has patched two critical vulnerabilities in its Apex One endpoint security platform that could allow remote code execution on vulnerable Windows systems. IT managers are advised to apply the updates immediately, especially those with on-premises instances, as the flaws affect the management console. Users of the software-as-a-service variant are already protected against these vulnerabilities.

ThreatCluster AI

Timeline

2022-09-15
CVE-2022-40139 added to CISA KEV (active exploitation)
2023-09-19
CVE-2023-41179 published
2025-08-05
CVE-2025-54987 published
2025-08-05
CVE-2025-54948 published
2026-02-25
Trend Micro announces critical vulnerabilities in Apex One
2026-02-26
Trend Micro releases patches for Apex One vulnerabilities

Community

Browse all →