CVE-2025-54948: Trend Micro Apex One
EPSS23.9%No. 1077 of 1739 in KEV
CVE year2025listed the same year
Same vendor in KEV12
Same product2
| Field | Value |
|---|---|
| Vendor | Trend Micro |
| Product | Apex One |
| Name | Trend Micro Apex One OS Command Injection Vulnerability |
| Added to KEV | 2025-08-18 |
| US federal due date | 2025-09-08 |
| Ransomware use | Unknown |
| CWE | CWE-78 |
CISA description
Trend Micro Apex One Management Console (on-premise) contains an OS command injection vulnerability that could allow a pre-authenticated remote attacker to upload malicious code and execute commands on affected installations.
Other entries for this product
| CVE | Vendor / product | Added | EPSS | Ransomware |
|---|---|---|---|---|
| CVE-2026-34926 | Trend Micro Apex One | 2026-05-21 | 0.5% | Unknown |
Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page
A Trend Micro Apex One vulnerability added to CISA's Known Exploited Vulnerabilities catalog on 2025-08-18.