# Trend Micro Apex One RCE flaws exploited

Published: 2025-08-18 · Severity: high · Sectors: technology
Canonical: https://vorant.io/reports/7bee34c5-7d59-5b58-a87e-b494b3acff35/trend-micro-apex-one-rce-flaws-exploited

> Two command injection vulnerabilities in Trend Micro Apex One management console are being actively exploited to achieve remote code execution.

Japan's IPA issued an alert regarding two command injection vulnerabilities (CVE-2025-54948 and CVE-2025-54987) affecting Trend Micro's Apex One, Apex One SaaS, and Standard Endpoint Protection products. The flaws exist in the management console and allow remote code execution, posing a significant risk given these are widely deployed endpoint security products.

As of the August 19 update, IPA confirmed the vulnerabilities are already being actively exploited in the wild, with potential for expanding damage. Trend Micro has released fixes and, for Apex One specifically, a mitigation tool called "FixTool_Aug2025" as an interim measure. Apex One SaaS and Standard Endpoint Protection users reportedly do not need to take independent action, suggesting those variants are managed/patched server-side by the vendor. IPA urges organizations running the on-premises Apex One product to apply patches urgently given confirmed exploitation.

## Mentioned in this report

- Vulnerabilities: CVE-2025-54948 (KEV), CVE-2025-54987

Source reporting: https://www.ipa.go.jp/security/security-alert/2025/alert20250807.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/7bee34c5-7d59-5b58-a87e-b494b3acff35/trend-micro-apex-one-rce-flaws-exploited.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
