Apex One Server Can Push Malicious Code Fleet-Wide

A medium directory traversal in Apex One is not a local server problem once an attacker has admin access. At that point, the management server becomes a code delivery path into every enrolled agent, so patching only the host misses the real blast radius. Trend Micro says CVE-2026-34926 has been exploited in the wild and has already been patched. CISA added it to KEV, and the flaw affects the on-premises version of Apex One, where an attacker can modify a key server table and inject code to deploy to agents on affected installations. The risk is bigger than one compromised management server. A foothold in Apex One can turn endpoint management into malware distribution across the fleet, and the same server model keeps the exposure even after the original traversal bug is fixed.

Part of the PlainSec briefing for 2026-05-23

Sources