Trend Micro Apex One (on-premise) directory traversal vulnerability (CVE-2026-34926) allows local attackers to inject malicious code into agents.
| Product | Version Start | Version End (excl.) | Status |
|---|---|---|---|
| apex_one | * | 14.0.0.17079 | vulnerable |
| apex_one | * | 14.0.20731 | vulnerable |
Download and install the latest security patches provided by Trend Micro specifically for Apex One on-premise installations to address the directory traversal flaw.
Ensure Apex One is updated to version 14.0.0.17079, 14.0.20731, or later, as all versions prior to these are confirmed to be vulnerable.
Implement strict Role-Based Access Control (RBAC) and the principle of least privilege to limit administrative access to the Apex One server, as exploitation requires local admin rights.
Audit server logs for directory traversal attempts and monitor the integrity of Apex One key tables and agent deployment packages for unauthorized changes.
Security teams should monitor Apex One server logs for suspicious directory traversal sequences (e.g., "../") within file path requests. Additionally, use File Integrity Monitoring (FIM) to detect unauthorized modifications to internal key tables and configuration files. Watch for unexpected agent update activities or the deployment of unsigned binaries from the Apex One server to managed endpoints, which may indicate a successful code injection attempt.
Experience superior visibility and a simpler approach to cyber risk management