Trend Micro Apex One Console Directory Traversal Remote Code Execution Vulnerability

Vulnerability

A remote code execution vulnerability has been identified in the Trend Micro Apex One management console. This issue arises from improper validation of user-supplied input, which can be exploited to execute arbitrary commands on the affected system. The vulnerability is present in Apex One 2019 (On-prem) for Windows) and in the SaaS version of Apex One as a Service, as well as Trend Vision One Endpoint - Standard Endpoint Protection. The vulnerability has been addressed in the latest Critical Patch for Apex One and the Security Agent Build 14.0.20315 for the SaaS version.

Impact

Exploitation of this vulnerability allows remote attackers to execute arbitrary code on the affected system, with the executed code running in the context of the IUSR account.

Remediation

Users of Trend Micro Apex One should apply the Critical Patch Build 14136, available through the Trend Micro Download Center. For the SaaS version, the latest Security Agent Build 14.0.20315 should be applied.

Added: May 21, 2026, 2:35 PM
Updated: May 21, 2026, 2:35 PM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
7.5
exploitability
7.2
remediation
7.9
relevance
8.5
threat
0.0
urgency
2.9
incentive
8.3

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.