Skip to main content
Mallory
MediumCISA KEVExploited in the wildPublic exploit

Directory Traversal in Trend Micro Apex One (On-Premise)

IdentifiersCVE-2026-34926CWE-23· Relative Path Traversal

CVE-2026-34926 is a directory traversal vulnerability affecting the on-premise Trend Micro Apex One server. According to the provided content, a pre-authenticated local attacker can exploit relative path traversal behavior to bypass intended filesystem restrictions, modify a key table on the Apex One server, and inject malicious code that is then deployed to Apex One agents on affected installations. The issue is limited to on-premise deployments; Trend Micro stated that exploitation requires the attacker to already have access to the Apex One Server and to have obtained administrative credentials to that server through another method. The vulnerability has been reported as actively exploited in the wild and has been added to CISA's Known Exploited Vulnerabilities catalog.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation allows an attacker to tamper with the Apex One server's internal data structures and use the server as a trusted distribution point for malicious code to managed endpoint agents. Because Apex One centrally manages endpoint protection across an enterprise, this can undermine the integrity of the security platform itself, enable broad downstream compromise of protected endpoints, and potentially impair or subvert endpoint detection and response functions. The content indicates active exploitation in the wild.

Mitigation

If you can’t patch tonight, do this now.

If immediate patching is not possible, restrict access to the Apex One server and management interface, review and reduce remote access paths to critical systems, verify that only authorized users retain administrative privileges on the Apex One Server console, and isolate the server from unnecessary local or administrative access. Increase monitoring for unauthorized changes to key tables, agent deployment activity, and anomalous agent configuration updates. Review recently deployed agent configurations and deployment logs for signs of malicious code injection or unauthorized modification.

Remediation

Patch, then assume compromise.

Apply Trend Micro's vendor-issued patches for the Apex One on-premise server and update affected security agents as soon as possible. The provided content also notes vendor guidance to patch both the server and the security agent for on-premise deployments. Organizations should review Trend Micro support/advisory materials for the specific fixed versions and deployment instructions. CISA has required remediation for affected federal agencies due to active exploitation.
PUBLIC EXPLOITS

Exploits

No valid public exploits. Mallory filtered out 1 candidate as fakes, detection scripts, or README-only repos.

VALID 0 / 1 TOTALView more in app

All candidate exploits were filtered out by Mallory's validation.

EXPOSURE SURFACE

Affected products & vendors

Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.

VendorProductType
Trend MicroApex Oneapplication
Trend MicroApexone Opapplication
Trend MicroApexone Saasapplication

Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.

ACTIVITY FEED

Recent activity

53 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

help net securityNews
May 26, 2026
Actively exploited Trend Micro Apex One flaw gets CISA warning (CVE-2026-34926) - Help Net Security

A relative directory path traversal vulnerability in Trend Micro Apex One that affects on-premise deployments and can allow an attacker with administrative access to the Apex One Server to modify a key table and inject malicious code for deployment to agents.

Read more
scworldNews
May 22, 2026
CISA adds Trend Micro Apex One and Langflow flaws to exploited vulnerabilities catalog | brief | SC Media

A directory traversal flaw in Trend Micro Apex One (on-premise) that allows a local attacker with administrative credentials to modify server tables and inject malicious code.

Read more
cyber security newsNews
May 22, 2026
CISA Warns of Trend Micro Apex One Vulnerability Exploited in Attacks

A critical directory traversal vulnerability in on-premise Trend Micro Apex One that can allow a pre-authenticated local attacker to manipulate file paths, access restricted directories, modify a key database table, and inject malicious code that can be distributed to connected endpoint agents.

Read more
the hacker newsNews
May 22, 2026
CISA Adds Exploited Langflow and Trend Micro Apex One Vulnerabilities to KEV

A directory traversal vulnerability affecting on-premise Trend Micro Apex One that allows a pre-authenticated local attacker with access to the Apex One Server and administrative credentials to modify a key table and inject malicious code for deployment to agents.

Read more
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence1

Every observed campaign linking this CVE to a named adversary.

Associated malware

Malware families riding this exploit, with evidence and IOCs.

Detection signatures1

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity42

Community discussion across Reddit, Mastodon, and other social sources.