CVE Feed

    Dashboard / CVE / CVE-2025-71210

    CVE-2025-71210

    A vulnerability in the Trend Micro Apex One management console could allow a remote attacker to upload malicious code and execute commands on affected installations. Please note: although this vulnerability carries a technical critical CVSS rating, this was reported via responsible disclosure via a researcher through the Zero Day Initiative. The SaaS versions of the product have already been mitigated and no customer action required. For this particular vulnerability, an attacker must have access to the Trend Micro Apex One Management Console, so customers that have their console�s IP address exposed externally should consider mitigating factors such as source restrictions if not already applied.

    Published:May 21, 2026
    Last Modified:Jun 18, 2026
    EPS:May 21, 2026
    EPSS Score:0.04019
    CVSS Score:9.8

    Affected Products

    Vendor
    Trendmicro
    Product
    Apex One
    Vendor
    Trendmicro
    Product
    Apexone Op
    Vendor
    Trendmicro
    Product
    Apexone Saas

    Exploits

    No exploit reference

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High