Fixing and finding
Jump to remediation plan
CVE ID

CVE-2026-34926

Published 2026-05-21
Updated 2 months ago
Vendor/s
Trend Micro
Product/s
Apex One
Version/s
* > 14.0.0.17079
KEV Status
Active Exploitation
Listed in CISA's Known Exploited Vulnerabilities catalog. Active exploitation observed in the wild.
CVSS Score (v3.1)
6.7
/ 10
Medium
Severity Details
Base score
6.7 Medium
Attack vector
Local
Attack complexity
High
Privileges required
High
User interaction
None
Scope
Changed
Confidentiality
High
Integrity
Low
Availability
Low

Description

Trend Micro Apex One (on-premise) directory traversal vulnerability (CVE-2026-34926) allows local attackers to inject malicious code into agents.

CPE

Trend Micro logo
Trend Micro
Product Version Start Version End (excl.) Status
apex_one * 14.0.0.17079 vulnerable
apex_one * 14.0.20731 vulnerable

Related weakness (CWE)

CWE-23

Remediation plan

1

Apply official patches

Download and install the latest security patches provided by Trend Micro specifically for Apex One on-premise installations to address the directory traversal flaw.

2

Update affected systems

Ensure Apex One is updated to version 14.0.0.17079, 14.0.20731, or later, as all versions prior to these are confirmed to be vulnerable.

3

Restrict access

Implement strict Role-Based Access Control (RBAC) and the principle of least privilege to limit administrative access to the Apex One server, as exploitation requires local admin rights.

4

Monitor for exploitation

Audit server logs for directory traversal attempts and monitor the integrity of Apex One key tables and agent deployment packages for unauthorized changes.

Detection Guidance

Security teams should monitor Apex One server logs for suspicious directory traversal sequences (e.g., "../") within file path requests. Additionally, use File Integrity Monitoring (FIM) to detect unauthorized modifications to internal key tables and configuration files. Watch for unexpected agent update activities or the deployment of unsigned binaries from the Apex One server to managed endpoints, which may indicate a successful code injection attempt.

References

Sources

NIST National Vulnerability Database (NVD)
CISA Known Exploited Vulnerabilities (KEV)

Experience superior visibility and a simpler approach to cyber risk management