← Vulnerability feed

Vulnerability record · CVE-2026-34926 · published 21 May 2026

CVE-2026-34926: Trend Micro Apex One on-premise server directory traversal enables agent code injection

Trendmicro · Apex One

A relative path traversal (CWE-23) in the Apex One on-premise server lets an attacker who already holds administrative credentials on the server modify a key table and inject malicious code that is then deployed to managed agents. Only the on-premise deployment is affected. Because the injected code reaches every agent the server manages, a single compromised server can push malicious payloads across the whole managed endpoint fleet.

6.7 CVSS 3.1 Medium CISA KEV since 21 May 2026 EPSS 0.54% · top 57.0% CWE-23 · Relative path traversal
6.7CVSS 3.1 base score
0.54%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
5References
23 Jul 2026Last modified by NVD

Description

A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations. This vulnerability is only exploitable on the on-premise version of Apex One and a potential attacker must have access to the Apex One Server and already obtained administrative credentials to the server via some other method to exploit this vulnerability.

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:L

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityThe flaw is in CISA KEV with a near-term remediation deadline and a high EPSS percentile, though exploitation requires pre-existing server admin credentials and local access.

What it is

A relative path traversal (CWE-23) in the Apex One on-premise server lets an attacker who already holds administrative credentials on the server modify a key table and inject malicious code that is then deployed to managed agents. Only the on-premise deployment is affected. Because the injected code reaches every agent the server manages, a single compromised server can push malicious payloads across the whole managed endpoint fleet.

Impact

An attacker with server admin access can tamper with the key table and distribute malicious code to all managed agents, giving control over endpoint protection across the estate. The scope change in the CVSS vector reflects that the compromise of the server extends to the agents it manages.

Attack surface

Reached locally on the Apex One on-premise server (AV:L) and requires high privileges (PR:H), meaning the attacker must already have administrative credentials obtained by other means; no user interaction is needed (UI:N). The flaw is not present in the SaaS/cloud version.

Exploitation

The vulnerability is listed in CISA KEV with a remediation due date of 2026-06-04, indicating known exploitation, and EPSS gives a 30-day probability of 0.12682 (96th percentile). No ransomware campaign use is documented.

What to do

  • Apply the Trend Micro vendor fix referenced in KA-0023430 (and the Japanese advisory KA-0022974) as the first action.
  • If patching is not immediately possible, follow CISA BOD 22-01 guidance or discontinue use of the on-premise Apex One server until mitigations are in place.
  • Restrict and audit administrative access to the Apex One server, since exploitation requires pre-existing admin credentials.
  • Review the server's key table and agent deployment configuration for unauthorized modifications.
  • Monitor managed agents for unexpected code or policy pushes originating from the server.

Detection

  • Audit Apex One server logs for unexpected changes to the key table or agent deployment configuration.
  • Alert on anomalous or out-of-band code/policy pushes to managed agents.
  • Correlate server-side file access events with traversal-style relative paths.
  • Review administrative account activity on the Apex One server for credential misuse or unusual logon patterns.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2026-34926 to the Known Exploited Vulnerabilities catalog on 21 May 2026 as "Trend Micro Apex One (On-Premise) Directory Traversal Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 4 June 2026.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-34926 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-54948Trend Micro Apex One management console OS command injectionThe on-premise Apex One management console contains an OS command injection flaw (CWE-78) that lets a remote attacker upload malicious code and run c…KEVEPSS 22%analysed9.8CVE-2022-26871Trend Micro Apex Central unauthenticated arbitrary file uploadTrend Micro Apex Central (and Apex One) contains an arbitrary file upload flaw caused by insufficient verification of data authenticity (CWE-345). An…KEVEPSS 19%analysed9.8CVE-2020-8599Trend Micro Apex One and OfficeScan EXE allows arbitrary file write and ROOT bypassTrend Micro Apex One (2019) and OfficeScan XG server ship a vulnerable EXE file that lets a remote, unauthenticated attacker write arbitrary data to …KEVEPSS 12%analysed8.8CVE-2021-36741Trend Micro Apex One and OfficeScan unrestricted file uploadTrend Micro Apex One, Apex One as a Service, OfficeScan XG and Worry-Free Business Security 10.0 SP1 fail to properly validate input, allowing an aut…KEVEPSS 5.0%analysed8.8CVE-2020-8468Trend Micro Apex One, OfficeScan and Worry-Free agents content validation escapeTrend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) agents contain a content validation escape flaw (CWE-74)…KEVEPSS 6.2%analysed8.8CVE-2020-8467Trend Micro Apex One and OfficeScan migration tool RCEA component of the migration tool in Trend Micro Apex One (2019) and OfficeScan XG allows remote attackers to execute arbitrary code on affected inst…KEVEPSS 11%analysed7.8CVE-2021-36742Trend Micro Apex One and OfficeScan improper input validation privilege escalationTrend Micro Apex One, Apex One as a Service, OfficeScan XG and Worry-Free Business Security 10.0 SP1 contain an improper input validation flaw (CWE-2…KEVEPSS 1.5%analysed7.8CVE-2020-24557Trend Micro Apex One and Worry-Free Business Security folder manipulation privilege escalationTrend Micro Apex One and Worry-Free Business Security 10.0 SP1 on Windows allow an attacker to manipulate a product folder to temporarily disable the…KEVEPSS 2.7%analysed

Source: NIST National Vulnerability Database (record CVE-2026-34926), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.