ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Actively exploited Trend Micro Apex One flaw gets CISA warning (CVE-2026-34926)

criticalVulnerability exploited in the wildimportance 60CVE-2026-34926

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-34926
Directory Traversal in Trend Micro Apex One (On-Premise) Server

CVE-2026-34926 is a directory traversal vulnerability (CWE-23) in the on-premise edition of the Trend Micro Apex One endpoint management server. A pre-authenticated local attacker — someone with access to the Apex One server who has already obtained administrative credentials through some other method — can use the traversal to modify a key table on the server, injecting malicious code that the server then deploys to its managed agents. This gives the attacker a delivery channel to run malicious code on the agents managed by the exploited server (CVSS scope changed), which is why the 6.7 CVSS score reflects a local, high-complexity, high-privilege attack path with high confidentiality impact. Only on-premise Apex One deployments are exploitable; the cloud/SaaS edition is not affected by this flaw. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2026-05-21 (EPSS 12.7%, 96th percentile), though no public proof-of-concept is known and ransomware use has not been confirmed.

Do: Apply Trend Micro's fix for the Apex One on-premise server per the vendor security advisory (exact fixed versions are not stated in the available data — check the bulletin), or, for US federal agencies, satisfy the BOD 22-01/KEV required action of applying vendor mitigations or discontinuing use if mitigations are unavailable. Because exploitation requires administrative credentials obtained by some other method, review privileged accounts on Apex One servers for compromise, check the server's key table for unauthorized modifications, and look for unexpected or anomalous code distributed to managed agents. Ransomware use is unconfirmed but plausible; restrict local and administrative access to the server and monitor agent activity until patched.

6.713% KEV
  • Trend Micro Apex One (on-premise server)
largetens of thousands of on-premise Apex One server deployments worldwide (managed agent population likely in the millions); not publicly quantified
Full article417 words · extracted from helpnetsecurity.com · click to collapse

A relative directory path traversal vulnerability (CVE-2026-34926) in Trend Micro’s Apex One platform has been exploited in zero-day attacks, the company confirmed.

CVE-2026-34926

“TrendAI has observed at least one attempt to exploit this vulnerability in the wild,” Trend Micro noted, and credited the incident response team of its TrendAI enterprise cybersecurity business for reporting it.

About Trend Micro Apex One

Trend Micro Apex One is a security platform that protects all the devices in an organization from cyber threats.

The solution relies on lightweight agents installed on organizations’ laptops, desktops, and servers, which quietly monitor for threats and can automatically block or quarantine anything suspicious.

All these agents report back to a central server, through which IT teams manage security policies, investigate incidents, and keep an eye on the devices.

About CVE-2026-34926

CVE-2026-34926 and seven additional vulnerabilities affecting Apex One security agents were disclosed by Trend Micro last week, but only CVE-2026-34926 was flagged as actively exploited.

“This vulnerability is only exploitable on the on-premise version of Apex One and a potential attacker must have access to the Apex One Server and already obtained administrative credentials to the server via some other method to exploit this vulnerability,” the company noted.

Once exploited, the vulnerability allows this “pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations.” A trusted distribution channel may therefore become a malware distribution channel.

What to do?

Trend Micro has yet to share details about the attack its experts responded to, but has urged customers to update their on-prem Apex One server deployments and security agents as soon as possible.

“In addition to timely application of patches and updated solutions, customers are also advised to review remote access to critical systems and ensure policies and perimeter security is up-to-date,” the company added.

It’s also a good idea to check whether only authorized users have access to and admin privileges on the Apex One Server console.

Customers using Trend Micro Apex One as a Service and TrendAI Vision One Endpoint Security – Standard Endpoint Protection should implement the security agent patches, as the server-side vulnerabilities have been patched by Trend Micro in April.

The US Cybersecurity and Infrastructure Security Agency added CVE-2026-34926 to its Known Exploited Vulnerabilities catalog, and ordered US federal civilian agencies to implement the patches by June 4, 2026.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2026/05/26/actively-exploited-trend-micro-apex-one-flaw-cve-2026-34926/