Trend Micro has fixed a security hole in Apex One that was used in attacks on Windows systems. Tracked as CVE-2026-34926, a directory traversal vulnerability in the Apex One (on-premise) server which could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations.
This vulnerability is only exploitable on the on-premise version of Apex One and a potential attacker must have access to the Apex One Server and already obtained administrative credentials to the server via some other method to exploit this vulnerability.
“A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations,” Trend Micro saidon Thursday.
“This vulnerability is only exploitable on the on-premise version of Apex One and a potential attacker must have access to the Apex One Server and already obtained administrative credentials to the server via some other method to exploit this vulnerability.”
Apex One is a security platform from Trend Micro designed to defend corporate networks against many threats, including malware, ransomware, attacks without files, and online dangers.
However, despite the restrictive requirements for successful exploitation, the company warned that “TrendAI has observed at least one attempt to exploit this vulnerability in the wild.”
Federal agencies ordered to patch within three weeks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) also listed CVE-2026-34926 as a threat being actively used and told federal agencies to fix their devices by June 4.
“These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise,” CISA warned. “Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.”
On Thursday, Trend Micro also released security updates to fix seven local privilege escalation flaws in the Apex One Standard Endpoint Protection (SEP) agent. These vulnerabilities can be exploited by attackers if they have permission to run low-privileged code on the target system.
“nginx-poolslip” NGINX 0-Day Affects Millions of NGINX Servers To RCE
InfoSecBulletin Cybersecurity for mankind
