CVE-2026-34926 Details
Description
A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations. This vulnerability is only exploitable on the on-premise version of Apex One and a potential attacker must have access to the Apex One Server and already obtained administrative credentials to the server via some other method to exploit this vulnerability.
A directory traversal vulnerability has been identified in the on-premise version of Trend Micro Apex One. This vulnerability allows a pre-authenticated local attacker with administrative credentials to modify a key table on the server, injecting malicious code that can be deployed to agents on affected installations. The vulnerability is not present in the cloud-based version of Apex One or in TrendAI Vision One Endpoint Security - Standard Endpoint Protection.
Users of Trend Micro Apex One (On-Premise) should apply Service Pack 1 Critical Patch B18012 for the server and Agent Build 14.0.18012. For those who have already applied the previous Critical Patch 17079 or installed a fresh 17079 build, no action is needed as they are already protected. Instructions for downloading the patch are available on the Trend Micro Download Center.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-34926 | CISA-ADP | Third Party AdvisoryUS Government Resource |
| https://jvn.jp/en/vu/JVNVU90583059/ | [email protected] | Third Party Advisory |
| https://success.trendmicro.com/en-US/solution/KA-0023430 | [email protected] | Vendor Advisory |
| https://success.trendmicro.com/ja-JP/solution/KA-0022974 | [email protected] | Vendor Advisory |
| https://www.jpcert.or.jp/english/at/2026/at260014.html | [email protected] | Third Party Advisory |
This CVE is in CISA's Known Exploited Vulnerabilities Catalog
Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.
| Vulnerability Name | Date Added | Due Date | Required Action |
|---|---|---|---|
| Trend Micro Apex One (On-Premise) Directory Traversal Vulnerability | May 21, 2026 | Jun 4, 2026 | Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-23 | Relative Path Traversal | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| trendmicro apex one | < 14.0.0.17079 < 14.0.20731 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 23, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 22, 2026 | Initial Analysis | [email protected] |
| May 21, 2026 | CVE Modified | CISA-ADP |
| May 21, 2026 | CVE CISA KEV Update | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
| May 21, 2026 | New CVE Received | [email protected] |