Unrated severityNVD Advisory· Published Aug 5, 2025· Updated Feb 26, 2026
CVE-2025-54987
CVE-2025-54987
Description
A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious code and execute commands on affected installations. This vulnerability is essentially the same as CVE-2025-54948 but targets a different CPU architecture.
Affected products
2- Trend Micro, Inc./Trend Micro Apex Onev5cpe:2.3:a:trendmicro:apexone_server:14.0.0.14039:*:*:*:*:*:*:*Range: 2019 (14.0)
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
1- ZDI-26-270: TrendAI Apex One Console Directory Traversal Remote Code Execution VulnerabilityZero Day Initiative · Apr 15, 2026