What is CVE-2026-34926?
A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations. This vulnerability is only exploitable on the on-premise version of Apex One and a potential attacker must have access to the Apex One Server and already obtained administrative credentials to the server via some other method to exploit this vulnerability.
Timeline
- 2026-05-21Published to the U.S. National Vulnerability Database (NVD)
- 2026-05-21Added to the CISA Known Exploited Vulnerabilities (KEV) catalog
- 2026-05-23First covered in a defend.network daily briefing
- 2026-06-04CISA federal remediation deadline (BOD 22-01)
- 2026-07-23NVD record last updated
CISA Known Exploited Vulnerability
Trend Micro Apex One (On-Premise) Directory Traversal Vulnerability
Affected product
Trend Micro Apex One
References
Referenced in our briefings & reports
Browse all tracked CVEs in the defend.network CVE database →
🤖 This CVE page is generated by defend.network from NVD, CISA KEV, EPSS, and our verified daily briefings. Severity and exploitation data come from official sources; always verify remediation steps against the official vendor advisory before acting in production.