JPCERT/CC warned that multiple vulnerabilities in TrendAI Apex One, Trend Micro Apex One as a Service, and TrendAI Vision One Endpoint Security - Standard Endpoint Protection could let attackers distribute crafted code to security agents or gain elevated privileges. Trend Micro said cloud-side fixes for the hosted products were applied during maintenance in April 2026, but endpoint agents still need to be updated to fully remediate the issue.
The most urgent flaw is the on-premises relative path traversal vulnerability CVE-2026-34926, which Trend Micro confirmed is already being exploited in attacks. JPCERT/CC urged organizations using the on-premises version of TrendAI Apex One to patch immediately, while customers of the cloud-based offerings should also update affected agents to close the remaining exposure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
On 2026-05-21, JPCERT/CC published advisory JPCERT-AT-2026-0014 covering multiple vulnerabilities in TrendAI Apex One, Apex One as a Service, and TrendAI Vision One Endpoint Security, and urged prompt patching.
Trend Micro confirmed that attackers were exploiting CVE-2026-34926, a relative path traversal vulnerability in the on-premises version of TrendAI Apex One, which could help distribute crafted code or enable privilege escalation.
Users were advised to update to the latest vendor-published versions of WPS Office2, WPS Cloud, WPS Cloud Pro, and KINGSOFT PDF Pro to remediate CVE-2018-6400.
LAC reported the WPS named-pipe access control flaw to IPA, and JPCERT/CC coordinated with the developer under Japan's Information Security Early Warning Partnership.
Trend Micro stated that server-side fixes for affected cloud-based products were applied during maintenance in April 2026, though endpoint security agents still required patching.
A local privilege escalation vulnerability later tracked as CVE-2018-6400 was originally reported around 2018, affecting a background service in WPS-related products that used a named pipe with insufficient access controls.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.