Vulnerabilities & Exploits · Web App Attack

Apex One Server Can Push Malicious Code Fleet-Wide

A medium directory traversal in Apex One is not a local server problem once an attacker has admin access. At that point, the management server becomes a code delivery path into every enrolled agent, so patching only the host misses the real blast radius.

Trend Micro says CVE-2026-34926 has been exploited in the wild and has already been patched. CISA added it to KEV, and the flaw affects the on-premises version of Apex One, where an attacker can modify a key server table and inject code to deploy to agents on affected installations.

The risk is bigger than one compromised management server. A foothold in Apex One can turn endpoint management into malware distribution across the fleet, and the same server model keeps the exposure even after the original traversal bug is fixed.

3 sources · May 26

CVE-2026-34926

NVD KEV

Known exploited · CISA KEV

CVSS 6.7 MEDIUM: a directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local…

CISA federal remediation date Jun 4

Timeline

Sources

Part of the PlainSec briefing for 2026-05-23

Every edition of this story: Apex One Server Can Push Malicious Code Fleet-Wide

More from today