Link Following Vulnerability in Trend Micro Apex One Scan Engine
CVE-2025-71212
7.8HIGH
Key Information:
- Vendor
Trend Micro
- Vendor
- CVE Published:
- 21 May 2026
What is CVE-2025-71212?
A vulnerability exists within the Trend Micro Apex One scan engine that allows a local attacker to escalate privileges through exploiting a link following weakness. To launch the attack, the attacker needs to have already executed low-privileged code on the affected system. This vulnerability poses a risk to the integrity and security of the affected installations, enabling potential unauthorized actions by an adversary.
Affected Version(s)
TrendAI Apex One 2019 (14.0) < 14.0.0.14136
TrendAI Apex One as a Service SaaS < 14.0.20315