CVE-2026-34926
Known exploited · CISA KEV
CVSS 6.7 MEDIUM: a directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local…
CISA federal remediation date Jun 4
Vulnerabilities · 111 days ago
A medium directory traversal in Apex One is not a local server problem once an attacker has admin access. At that point, the management server becomes a code delivery path into every enrolled agent, so patching only the host misses the real blast radius.
Trend Micro says CVE-2026-34926 has been exploited in the wild and has already been patched. CISA added it to KEV, and the flaw affects the on-premises version of Apex One, where an attacker can modify a key server table and inject code to deploy to agents on affected installations.
The risk is bigger than one compromised management server. A foothold in Apex One can turn endpoint management into malware distribution across the fleet, and the same server model keeps the exposure even after the original traversal bug is fixed.
Known exploited · CISA KEV
CVSS 6.7 MEDIUM: a directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local…
CISA federal remediation date Jun 4
3 sources covering this story
Actively exploited Trend Micro Apex One flaw gets CISA warning (CVE-2026-34926) - Help Net Security
A relative directory path traversal vulnerability (CVE-2026-34926) in Trend Micro's Apex One platform has been exploited in zero-day attacks.
Trend Micro warns of Apex One zero-day exploited in the wild
Japanese cybersecurity software company Trend Micro has addressed an Apex One zero-day vulnerability exploited in attacks targeting Windows systems.
TrendAI Patches Apex One Zero-Day Exploited in the Wild
CVE-2026-34926 is a directory traversal flaw that can be exploited against the on-premise version of Apex One.
Part of the PlainSec briefing for 2026-05-23