CVE-2026-34926
Sfruttamento noto · CISA KEV
CVSS 6.7 MEDIUM: a directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local…
Data di correzione federale CISA 4 giu
Vulnerabilità ed exploit · Attacco ad app web
Un directory traversal di media gravità in Apex One non è solo un problema del server locale una volta che un attaccante ha accesso admin. A quel punto, il management server diventa un percorso di consegna del codice verso ogni agent registrato, quindi la patch del solo host non coglie il vero blast radius.
3 fonti · 26 mag
Sfruttamento noto · CISA KEV
CVSS 6.7 MEDIUM: a directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local…
Data di correzione federale CISA 4 giu
Help Net Security
Actively exploited Trend Micro Apex One flaw gets CISA warning (CVE-2026-34926) - Help Net Security
A relative directory path traversal vulnerability (CVE-2026-34926) in Trend Micro's Apex One platform has been exploited in zero-day attacks.
originaleBleepingComputer
Trend Micro warns of Apex One zero-day exploited in the wild
Japanese cybersecurity software company Trend Micro has addressed an Apex One zero-day vulnerability exploited in attacks targeting Windows systems.
originaleSecurityWeek
TrendAI Patches Apex One Zero-Day Exploited in the Wild
CVE-2026-34926 is a directory traversal flaw that can be exploited against the on-premise version of Apex One.
originalePart of the PlainSec briefing for 2026-05-23
Every edition of this story: Apex One Server Può Inviare Codice Malevolo a Tutta la Flotta