A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious code and execute commands on affected installations.
Conclusion & alert: CVE-2025-54948 is rated Critical Active Threat (100/100): CVSS Critical severity, with high exploitation likelihood (EPSS 13.89%, 94th percentile).Core evidence: CISA KEV confirms active exploitation (added 2025-08-18) affecting Trend Micro / Apex One. a weakness (CWE-78) Unauthenticated remote administrative access may be possible. EPSS rose +5.07% over the last day, indicating growing attacker interest.Mandatory action: The CISA remediation deadline has passed—treat as an emergency patch priority.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
CISA KEV Record for CVE-2025-54948
Name: Trend Micro Apex One OS Command Injection Vulnerability · CISA KEV detail
Exploit added: 2025-08-18
Action due: 2025-09-08
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Exploit prediction scoring system (EPSS) score for CVE-2025-54948
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).