CVE-2026-34926

Confirmed PUBLISHED

A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the...

Trend Micro, Inc. · TrendAI Apex One, TrendAI Apex One as a Service

1 day faster than CISA KEV

Exploited in the wild PoC available

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
6.7 Medium EPSS 12.7%

At a Glance

A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations. This vulnerability is only exploitable on the on-premise version of Apex One and a potential attacker must have access to the Apex One Server and already obtained administrative credentials to the server via some other method to exploit this vulnerability.

cisa
CVE Published
May 21, 2026
Exploitation Reported
Jun 01, 2026
CVSS
6.7 Medium
EPSS
12.7%
No user interaction

Affected Versions

Vendor Product Version Status
Trend Micro, Inc.
TrendAI Apex One

2019 (14.0) to < 14.0.0.17079

Affected
Trend Micro, Inc.
TrendAI Apex One as a Service

SaaS to < 14.0.20731

Affected

CVE References

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.