LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-34926: Trend Micro Apex One (On-Premise) Directory Traversal Vulnerability

RBRecent Breaches Vulnerability Intelligence·May 21, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jun 4, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-34926 to its Known Exploited Vulnerabilities catalog on May 21, 2026, with a federal patch deadline of Jun 4, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Trend Micro Apex One (on-premise) contains a directory traversal vulnerability that could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to…

Trend Micro Apex One on-premise servers contain a directory traversal vulnerability. A pre-authenticated local attacker can modify a key table on the server and inject malicious code intended for deployment to managed agents. The issue affects organizations that rely on this endpoint protection platform for centralized management and agent updates.

How it works

The weakness is categorized as CWE-23, a directory traversal flaw. An attacker with local access and pre-authentication can supply crafted paths that reach and alter a designated table used by the server. Successful modification allows the attacker to insert malicious code that the server later distributes to connected agents on the same installation.

Am I affected? How to find it in your systems

Inventory all on-premise deployments of Trend Micro Apex One, including management servers and any consoles that handle agent communication and updates. Check the exact product version and configuration settings against the vendor advisory to determine exposure. Review server file-system and process activity logs for unexpected modifications to internal tables or configuration stores; no public exploit indicators are specified, so treat anomalous write attempts to management components as potential signs of attempted abuse.

How to remediate

Apply the vendor-supplied update referenced in the official advisory as the primary step. After patching, review and restrict local account privileges on the management server to the minimum required for operations. Limit network access to the server to only the necessary management and agent subnets.

If you can't patch immediately

Follow the mitigations listed in the vendor advisory. Apply any applicable guidance from CISA BOD 22-01 for related cloud services. Where mitigations cannot be implemented, discontinue use of the affected on-premise installation until remediation is complete. Monitor server logs and agent deployment channels for unexpected code or configuration changes.

If your data may have been exposed

Directory traversal issues that permit code injection on management servers have led to broader compromise in similar products. Organizations can run a free exposure scan of their email addresses to check for presence in known breach data sets.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedTrend Micro · Apex One
WeaknessCWE-23
Added to CISA KEVMay 21, 2026
Federal patch deadlineJun 4, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities