Trend Micro Apex One Console Directory Traversal Remote Code Execution Vulnerability

Vulnerability

A directory traversal vulnerability allowing remote code execution has been identified in the Trend Micro Apex One management console. This issue arises from improper validation of user-supplied input, which can be exploited to execute arbitrary commands on the affected system. The vulnerability affects Apex One 2019 (On-prem) installations on Windows, as well as the SaaS version of Apex One as a Service and Trend Vision One Endpoint - Standard Endpoint Protection. The console listens on TCP ports 8080 and 4343 by default.

Impact

Exploitation of this vulnerability allows remote attackers to execute arbitrary code on the affected system, with the executed code running in the context of the IUSR account.

Remediation

Trend Micro has released a Critical Patch for Apex One 2019 (On-prem) users. This patch can be downloaded from the Trend Micro Download Center. For Apex One as a Service and Trend Vision One Endpoint - Standard Endpoint Protection users, the update has already been applied via the latest SaaS updates.

Added: May 21, 2026, 2:48 PM
Updated: May 21, 2026, 2:48 PM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
7.5
exploitability
7.2
remediation
7.9
relevance
9.0
threat
0.0
urgency
2.9
incentive
8.3

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.