CyberzSOC

Publication detail
← Back to advisories & guidance

[Updated]Alert Regarding Multiple OS Command Injection Vulnerabilities in Trend Micro Multiple Endpoint Security Products for Enterprises ↗ source

August 18, 2025 JPCERT/CC Alert

Summary

If these vulnerabilities are exploited, an unauthenticated attacker may execute arbitrary code. Trend Micro Incorporated has reported that attacks exploiting CVE-2025-54948 have been observed in the wild. Since the vulnerabilities are already being exploited in the wild, the users of the affected products are recommended to update the affected system to the latest version as soon as possible. ITW CRITICAL SECURITY BULLETIN: Trend Micro Apex One (On-Premise) Management Console Command Injection RCE Vulnerabilities [Important Notice] Respond to Confirmed Attacks Exploiting Vulnerabilities in Trend Micro Endpoint Security Products (Text in Japanese) Affected products and versions are as follows: As for Trend Micro Apex One as a Service and Trend Vision One Endpoint Security - Standard Endpoint Protection, the vulnerabilities have already been mitigated in the July 31, 2025 updates. The users of Trend Micro Apex One On Premise (2019) are recommended to apply Fixtool.

News Coverage

Articles from the monitored vendor research blogs and security news feeds that reference a CVE cited in this publication, or name the campaign it covers. Coverage begins when feed monitoring started; earlier articles are not indexed.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2025-54948 9.4 Critical Trend Micro Apex One Trend Micro Apex One Management Console (on-premise) contains an OS command injection vulnerability that could allow a pre-authenticated remote attac…
CVE-2025-54987 9.4 Critical Trend Micro, Inc. Trend Micro Apex One A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious code and …

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.