← Back to Vulnerability Reports CVE Intelligence

CVE-2026-34926

Trend Micro Apex OneMEDIUM · CVSS 6.7 In the wild In CISA KEV

What is CVE-2026-34926?

A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations. This vulnerability is only exploitable on the on-premise version of Apex One and a potential attacker must have access to the Apex One Server and already obtained administrative credentials to the server via some other method to exploit this vulnerability.

CVSS6.7 NVD 3.1
SeverityMEDIUM
Exploitation In the wild In CISA KEV
Triage statusActive Exploit
ActionPatch immediately
CVSS vectorCVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:L
NVD published2026-05-21
NVD last modified2026-05-22

CISA Known Exploited Vulnerability

Trend Micro Apex One (On-Premise) Directory Traversal Vulnerability

Added to KEV2026-05-21
Federal patch deadline2026-06-04
Known ransomware useUnknown

Affected product

Trend Micro Apex One

🤖 This CVE page is generated by defend.network from NVD, CISA KEV, EPSS, and our verified daily briefings. Severity and exploitation data come from official sources; always verify remediation steps against the official vendor advisory before acting in production.

Get Critical CVE Alerts

Subscribe free and hear about actively exploited CVEs like this one first.