H-ISAC TLP White Threat Bulletin: Trend Micro Discloses Two Exploited Critical Flaws (CVE-2025-54948 and CVE-2025-54987)

On August 5, Trend Micro issued an urgent for two critical vulnerabilities, CVE-2025-54948 and CVE-2025-54987, affecting on-premise versions of its Apex One Management Console. TrendMicro has observed at least one attempt to exploit these vulnerabilities in the wild.

Both flaws are pre-authenticated remote code execution and command injection vulnerabilities. Threat actors could use these flaws to upload malicious code and execute commands on the affected server. The flaws are essentially the same, with the only difference being that they target different CPU architectures. The assigned CVSS score is 9.4 for both flaws, highlighting their criticality.

To exploit these flaws, threat actors would need access to the Trend Micro Apex One Management Console. This puts customers whose IP addresses are exposed externally at a higher risk. As a mitigation, these customers are advised to implement source restrictions.

TrendMicro has released temporary fixes; a more formal patch is expected for mid-August.

For help with Cybersecurity and Risk Advisory Services exclusively for AHA members, contact:

John Riggi

National Advisor for Cybersecurity and Risk, AHA

jriggi@aha.org

(O) +1 202 626 2272