CVE-2025-54948

A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious code and execute commands on affected installations.

  • Published Aug 5, 2025
  • CVSS 9.8 critical
  • 23.9% chance of exploitation in the next 30 days (EPSS)
  • In CISA's Known Exploited Vulnerabilities catalog
  • A fix is available

Affected software

CVE-2025-54948 at the National Vulnerability Database