Vulnerability record · CVE-2026-34926 · published 21 May 2026
CVE-2026-34926: Trend Micro Apex One on-premise server directory traversal enables agent code injection
Trendmicro · Apex One
A relative path traversal (CWE-23) in the Apex One on-premise server lets an attacker who already holds administrative credentials on the server modify a key table and inject malicious code that is then deployed to managed agents. Only the on-premise deployment is affected. Because the injected code reaches every agent the server manages, a single compromised server can push malicious payloads across the whole managed endpoint fleet.
Description
A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations. This vulnerability is only exploitable on the on-premise version of Apex One and a potential attacker must have access to the Apex One Server and already obtained administrative credentials to the server via some other method to exploit this vulnerability.
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:L
Automated analysis
high priorityThe flaw is in CISA KEV with a near-term remediation deadline and a high EPSS percentile, though exploitation requires pre-existing server admin credentials and local access.
What it is
A relative path traversal (CWE-23) in the Apex One on-premise server lets an attacker who already holds administrative credentials on the server modify a key table and inject malicious code that is then deployed to managed agents. Only the on-premise deployment is affected. Because the injected code reaches every agent the server manages, a single compromised server can push malicious payloads across the whole managed endpoint fleet.
Impact
An attacker with server admin access can tamper with the key table and distribute malicious code to all managed agents, giving control over endpoint protection across the estate. The scope change in the CVSS vector reflects that the compromise of the server extends to the agents it manages.
Attack surface
Reached locally on the Apex One on-premise server (AV:L) and requires high privileges (PR:H), meaning the attacker must already have administrative credentials obtained by other means; no user interaction is needed (UI:N). The flaw is not present in the SaaS/cloud version.
Exploitation
The vulnerability is listed in CISA KEV with a remediation due date of 2026-06-04, indicating known exploitation, and EPSS gives a 30-day probability of 0.12682 (96th percentile). No ransomware campaign use is documented.
What to do
- Apply the Trend Micro vendor fix referenced in KA-0023430 (and the Japanese advisory KA-0022974) as the first action.
- If patching is not immediately possible, follow CISA BOD 22-01 guidance or discontinue use of the on-premise Apex One server until mitigations are in place.
- Restrict and audit administrative access to the Apex One server, since exploitation requires pre-existing admin credentials.
- Review the server's key table and agent deployment configuration for unauthorized modifications.
- Monitor managed agents for unexpected code or policy pushes originating from the server.
Detection
- Audit Apex One server logs for unexpected changes to the key table or agent deployment configuration.
- Alert on anomalous or out-of-band code/policy pushes to managed agents.
- Correlate server-side file access events with traversal-style relative paths.
- Review administrative account activity on the Apex One server for credential misuse or unusual logon patterns.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2026-34926 to the Known Exploited Vulnerabilities catalog on 21 May 2026 as "Trend Micro Apex One (On-Premise) Directory Traversal Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 4 June 2026.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://jvn.jp/en/vu/JVNVU90583059/ | Third Party Advisory |
| https://success.trendmicro.com/en-US/solution/KA-0023430 | Vendor Advisory |
| https://success.trendmicro.com/ja-JP/solution/KA-0022974 | Vendor Advisory |
| https://www.jpcert.or.jp/english/at/2026/at260014.html | Third Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-34926 | Third Party AdvisoryUS Government Resource |
Track CVE-2026-34926 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-34926), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.