Moneycontrol PRO
Swing Trading 101
Swing Trading 101

Government issues serious warning for this antivirus program: Here's what you need to know

Government has warned users of Trend Micro Apex One about critical vulnerabilities that allow privilege escalation and unauthorised access, urging organisations to apply patches immediately to prevent potential system compromise.

March 04, 2026 / 15:21 IST
Antivirus
Snapshot AI
  • CERT-In warns of critical flaws in Trend Micro Apex One products
  • Vulnerabilities allow remote attacks and privilege escalation
  • Users urged to apply patches promptly to prevent exploitation

The Indian Computer Emergency Response Team (CERT-In), under the Ministry of Electronics and Information Technology, has issued a critical vulnerability note for Trend Micro Apex One, warning users about multiple security flaws that could expose systems to remote attacks and privilege escalation.

According to CERT-In Vulnerability Note CIVN-2026-0111, the vulnerabilities affect Apex One 2019 (on-premises and SaaS), Trend Micro Apex One (macOS), and Trend Vision One Endpoint – Standard Endpoint Protection (SaaS). The advisory was originally issued on February 27, 2026, and carries a “Critical” severity rating.

What is the issue?

CERT-In said multiple vulnerabilities have been identified in Trend Micro Apex One components, including the management console, scan engine, and macOS agent.

One of the major flaws involves directory traversal vulnerabilities in the Apex One Management Console. These could allow a remote attacker to upload malicious files and execute arbitrary commands on affected installations. The advisory references CVE-2025-71210 and CVE-2025-71211 in this category.

In addition, multiple local privilege escalation vulnerabilities have been reported in the Apex One Scan Engine (CVE-2025-71212 and CVE-2025-71213). These issues could allow a locally authenticated attacker to gain elevated privileges on the system.

Another local privilege escalation vulnerability (CVE-2025-71214) affects the macOS Agent iCore service due to improper origin validation.

What Trend Micro has to say

In a statement shared with Moneycontrol, Trend Micro made it clear that the vulnerabilities were disclosed to customers, "The recent advisory issued by CERT-In relates to vulnerabilities in Trend Micro Apex One that were disclosed as part of our proactive and mandatory transparency process to keep customers informed and it is not in response to any security incident." Furthermore, the company said that there wasn't any impact on customers. "Patches and mitigation guidance have already been released to customers. Ongoing monitoring confirms our internal environments and customer deployments remain secure, with no reported customer impact."

Who is at risk?

The advisory is targeted at IT administrators, Security Operations Center (SOC) teams, cybersecurity analysts, system engineers, and executive management, including CISOs and IT leadership. CERT-In has warned that the risk includes service interruption and unauthorised access, with potential impact on the confidentiality, integrity, and availability of affected systems.

 

Invite your friends and family to sign up for MC Tech 3, our daily newsletter that breaks down the biggest tech and startup stories of the day

MC Tech Desk Read the latest and trending tech news—stay updated on AI, gadgets, cybersecurity, software updates, smartphones, blockchain, space tech, and the future of innovation.
first published: Mar 2, 2026 02:57 pm

Discover the latest Business News, Sensex, and Nifty updates. Obtain Personal Finance insights, tax queries, and expert opinions on Moneycontrol or download the Moneycontrol App to stay updated!

Subscribe to Tech Newsletters

  • On Saturdays

    Find the best of Al News in one place, specially curated for you every weekend.

  • Daily-Weekdays

    Stay on top of the latest tech trends and biggest startup news.

Advisory Alert: It has come to our attention that certain individuals are representing themselves as affiliates of Moneycontrol and soliciting funds on the false promise of assured returns on their investments. We wish to reiterate that Moneycontrol does not solicit funds from investors and neither does it promise any assured returns. In case you are approached by anyone making such claims, please write to us at grievanceofficer@nw18.com or call on 02268882347