CISA added CVE-2026-34926 to its Known Exploited Vulnerabilities catalog after confirming active exploitation of a critical Trend Micro Apex One on-premise flaw. The vulnerability is a directory traversal issue that can be abused by a pre-authenticated local attacker to manipulate file paths, access restricted directories, alter a key database table, and inject malicious code that may then be pushed to connected endpoint agents. Because Apex One centrally manages endpoint protection, a successful compromise could weaken EDR visibility and turn the management server into a distribution point for enterprise-wide malware.
Trend Micro issued advisories covering multiple vulnerabilities across Apex One (on-premise), Apex One as a Service, and Trend Vision One Endpoint / Standard Endpoint Protection, with affected builds including Apex One server and agent versions prior to 2019 build 17079 and SEP agent versions prior to 14.0.20731. National cyber authorities in Canada, Germany, and Hong Kong circulated related alerts, while CISA directed U.S. federal agencies to remediate the exploited flaw by June 4, 2026 and urged organizations to apply vendor updates, restrict local access to Apex One servers, and increase monitoring for signs of compromise.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Alongside the KEV listing, CISA directed U.S. federal civilian agencies to remediate the Trend Micro Apex One vulnerability by 2026-06-04 under Binding Operational Directive 22-01. CISA also urged organizations to patch immediately, restrict local server access, follow Trend Micro guidance, and strengthen monitoring.
CISA added CVE-2026-34926, a critical directory traversal vulnerability in Trend Micro Apex One on-premise, to its Known Exploited Vulnerabilities catalog because it was being actively exploited in attacks. The flaw can let a pre-authenticated local attacker manipulate file paths, alter a key database table, and inject malicious code to connected endpoint agents.
Multiple national cybersecurity bodies, including Germany's dCERT and Hong Kong CERT, published advisories warning about multiple Trend Micro Apex One vulnerabilities that could enable privilege escalation and code execution. These notices amplified vendor guidance and alerted defenders to the risk.
Trend Micro published a security advisory covering vulnerabilities in Apex One (on-premise), Apex One as a Service, and Trend Vision One Endpoint - Standard Endpoint Protection. The advisory identified affected builds and provided updates for vulnerable Apex One on-premise servers and agents and SEP agents.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
8 references tracked. Mallory keeps watching after this page renders.
helpnetsecurity.com
Open sourcescworld.com
Open sourcecybersecuritynews.com
Open sourcethecyberthrone.in
Open sourcebleepingcomputer.com
Open sourcehkcert.org
Open sourcedcert.de
Open sourcecyber.gc.ca
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.