Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
MediumCISA KEVExploited in the wildPublic exploit

Directory Traversal in Trend Micro Apex One (On-Premise)

IdentifiersCVE-2026-34926CWE-23· Relative Path Traversal

CVE-2026-34926 is a directory traversal vulnerability affecting the on-premise Apex One server from Trend Micro. According to the provided content, a pre-authenticated local attacker can exploit relative path traversal behavior to bypass intended filesystem restrictions, modify a key table on the Apex One server, and inject malicious code that is then deployed to Apex One agents on affected installations. The issue is limited to on-premise deployments; Trend Micro stated that exploitation requires the attacker to already have access to the Apex One Server and to have obtained administrative credentials to the server through another method. The content also states that Trend Micro observed at least one attempted in-the-wild exploitation and that CISA added the vulnerability to the KEV catalog.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation allows an attacker to tamper with the Apex One server’s trusted management and distribution workflow by modifying a key server table and injecting malicious code for deployment to managed agents. Because Apex One centrally manages endpoint security agents, this can convert the product’s trusted agent deployment/update path into a malware distribution mechanism, potentially enabling broad compromise of protected endpoints, unauthorized modification of security infrastructure, and degradation or subversion of endpoint protection across the environment.

Mitigation

If you can’t patch tonight, do this now.

If immediate patching is not possible, restrict access to the Apex One server and management interface as much as possible, ensure only authorized administrators retain access to the Apex One Server console, review and reduce remote access exposure to critical systems, and enforce least-privilege controls around the server. Increase monitoring for suspicious database/key table changes, unexpected agent deployment behavior, and unauthorized modifications to server-side components or agent configurations. Keep perimeter security policies current and isolate the Apex One management server where feasible.

Remediation

Patch, then assume compromise.

Apply Trend Micro’s vendor-issued patches/updates for Apex One on-premise, including the Apex One server and relevant security agents, as referenced in the provided content. Trend Micro and JPCERT/CC recommend prompt patching because the vulnerability has been exploited in the wild. Organizations should also review recently deployed agent configurations and deployment activity for unauthorized modifications or anomalous code injection patterns, and validate the integrity of the Apex One environment after patching.
PUBLIC EXPLOITS

Exploits

No valid public exploits. Mallory filtered out 1 candidate as fakes, detection scripts, or README-only repos.

VALID 0 / 1 TOTALView more in app

All candidate exploits were filtered out by Mallory's validation.

EXPOSURE SURFACE

Affected products & vendors

Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.

VendorProductType
Trend MicroApex Oneapplication
Trend MicroApexone Opapplication
Trend MicroApexone Saasapplication

Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.

ACTIVITY FEED

Recent activity

64 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

help net securityNews
May 26, 2026
Actively exploited Trend Micro Apex One flaw gets CISA warning (CVE-2026-34926) - Help Net Security

A relative directory path traversal vulnerability in Trend Micro Apex One that affects on-premise deployments and can allow an attacker with administrative access to the Apex One Server to modify a key table and inject malicious code for deployment to agents.

Read more
scworldNews
May 22, 2026
CISA adds Trend Micro Apex One and Langflow flaws to exploited vulnerabilities catalog | brief | SC Media

A directory traversal flaw in Trend Micro Apex One (on-premise) that allows a local attacker with administrative credentials to modify server tables and inject malicious code.

Read more
cyber security newsNews
May 22, 2026
CISA Warns of Trend Micro Apex One Vulnerability Exploited in Attacks

A critical directory traversal vulnerability in on-premise Trend Micro Apex One that can allow a pre-authenticated local attacker to manipulate file paths, access restricted directories, modify a key database table, and inject malicious code that can be distributed to connected endpoint agents.

Read more
the hacker newsNews
May 22, 2026
CISA Adds Exploited Langflow and Trend Micro Apex One Vulnerabilities to KEV

A directory traversal vulnerability affecting on-premise Trend Micro Apex One that allows a pre-authenticated local attacker with access to the Apex One Server and administrative credentials to modify a key table and inject malicious code for deployment to agents.

Read more
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence1

Every observed campaign linking this CVE to a named adversary.

Associated malware

Malware families riding this exploit, with evidence and IOCs.

Detection signatures1

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity53

Community discussion across Reddit, Mastodon, and other social sources.