ZeroHour

CVE-2026-34926

KEVlarge

Directory Traversal in Trend Micro Apex One (On-Premise) Server

CISA: Trend Micro Apex One (On-Premise) Directory Traversal Vulnerability

CVSS 3.1
6.7 medium
EPSS
13%p96
Published
()
KEV added
AI analysis

CVE-2026-34926 is a directory traversal vulnerability (CWE-23) in the on-premise edition of the Trend Micro Apex One endpoint management server. A pre-authenticated local attacker — someone with access to the Apex One server who has already obtained administrative credentials through some other method — can use the traversal to modify a key table on the server, injecting malicious code that the server then deploys to its managed agents. This gives the attacker a delivery channel to run malicious code on the agents managed by the exploited server (CVSS scope changed), which is why the 6.7 CVSS score reflects a local, high-complexity, high-privilege attack path with high confidentiality impact. Only on-premise Apex One deployments are exploitable; the cloud/SaaS edition is not affected by this flaw. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2026-05-21 (EPSS 12.7%, 96th percentile), though no public proof-of-concept is known and ransomware use has not been confirmed.

What to do: Apply Trend Micro's fix for the Apex One on-premise server per the vendor security advisory (exact fixed versions are not stated in the available data — check the bulletin), or, for US federal agencies, satisfy the BOD 22-01/KEV required action of applying vendor mitigations or discontinuing use if mitigations are unavailable. Because exploitation requires administrative credentials obtained by some other method, review privileged accounts on Apex One servers for compromise, check the server's key table for unauthorized modifications, and look for unexpected or anomalous code distributed to managed agents. Ransomware use is unconfirmed but plausible; restrict local and administrative access to the server and monitor agent activity until patched.

Affected
Trend Micro Apex One (on-premise server)
Estimated exposure
largetens of thousands of on-premise Apex One server deployments worldwide (managed agent population likely in the millions); not publicly quantified — Trend Micro publishes no active-install counts for Apex One on-premise, so this order-of-magnitude estimate is inferred from the product's long-standing enterprise endpoint-security market share and the large legacy OfficeScan/Apex One…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations. This vulnerability is only exploitable on the on-premise version of Apex One and a potential attacker must have access to the Apex One Server and already obtained administrative credentials to the server via some other method to exploit this vulnerability.

CISA Known Exploited Vulnerability
Affected
Trend Micro Apex One
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
trendmicro
Products
apex one
Weakness
CWE-23
Vector
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:L

In the news