CVE-2026-34926Active Exploitation(trendmicro / apex_one)

HIGHCVSS 6.7 · MEDIUMCISA KEV

Exploitation observed; activity peaked at 17 mentions and remains active

Immediate actions

  • Patch trendmicro apex_one systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations. This vulnerability is only exploitable on the on-premise version of Apex One and a potential attacker must have access to the Apex One Server and already obtained administrative credentials to the server via some other method to exploit this vulnerability.

6.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-06-04. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-23

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • apex_one

Threat summary

  • Active exploitation appears in 45 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 55 mentions across 15 observed days

What's happening

  • Active exploitation reported across 45 signals
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 22 signals
  • Technical details provided in 35 signals
  • Disclosure: 8 classified signals
  • Peaked 13d ago at 17 mentions (2026-05-22); latest day: 1
  • 55 total mentions across 15 days

Affected systems

Vendors
Products
apex_one

Deep dive

Activity timeline55 mentions / 15d
0491317Mentions · 2026-05-21: 9Mentions · 2026-05-22: 17Mentions · 2026-05-23: 3Mentions · 2026-05-24: 3Mentions · 2026-05-25: 2Mentions · 2026-05-26: 6Mentions · 2026-05-27: 5Mentions · 2026-05-28: 1Mentions · 2026-05-29: 2Mentions · 2026-06-01: 1Mentions · 2026-06-05: 1Mentions · 2026-06-10: 2Mentions · 2026-06-12: 1Mentions · 2026-06-22: 1Mentions · 2026-06-23: 1PoC Mentioned / Linked · 2026-05-22: 1PoC Mentioned / Linked · 2026-06-10: 1Active Exploitation · 2026-05-21: 6Active Exploitation · 2026-05-22: 16Active Exploitation · 2026-05-23: 3Active Exploitation · 2026-05-24: 2Active Exploitation · 2026-05-25: 1Active Exploitation · 2026-05-26: 6Active Exploitation · 2026-05-27: 4Active Exploitation · 2026-05-28: 1Active Exploitation · 2026-05-29: 1Active Exploitation · 2026-06-01: 1Active Exploitation · 2026-06-05: 1Active Exploitation · 2026-06-10: 1Active Exploitation · 2026-06-12: 1Active Exploitation · 2026-06-22: 1Patch / Workaround · 2026-05-21: 2Patch / Workaround · 2026-05-22: 11Patch / Workaround · 2026-05-23: 2Patch / Workaround · 2026-05-24: 2Patch / Workaround · 2026-05-26: 2Patch / Workaround · 2026-05-27: 1Patch / Workaround · 2026-05-29: 1Patch / Workaround · 2026-06-12: 1Technical Details · 2026-05-21: 8Technical Details · 2026-05-22: 11Technical Details · 2026-05-23: 2Technical Details · 2026-05-24: 2Technical Details · 2026-05-25: 1Technical Details · 2026-05-26: 2Technical Details · 2026-05-27: 3Technical Details · 2026-05-28: 1Technical Details · 2026-05-29: 1Technical Details · 2026-06-01: 1Technical Details · 2026-06-05: 1Technical Details · 2026-06-10: 1Technical Details · 2026-06-23: 105-2105-2205-2305-2405-2505-2605-2705-2805-2906-0106-0506-1006-1206-2206-23
Signal classification4 categories
Active Exploitation
3869.1%
Disclosure
814.5%
Patch
712.7%
General
23.6%
Referenced assets50 URLs
By indicator
Classification over time
DateTotalLabels
2026-05-219
Active Exploitation6Disclosure1General2
2026-05-2217
Active Exploitation10Disclosure1Patch6
2026-05-233
Active Exploitation3
2026-05-243
Active Exploitation2Disclosure1
2026-05-252
Active Exploitation1Disclosure1
2026-05-266
Active Exploitation6
2026-05-275
Active Exploitation4Disclosure1
2026-05-281
Active Exploitation1
2026-05-292
Disclosure1Patch1
2026-06-011
Active Exploitation1
2026-06-051
Active Exploitation1
2026-06-102
Active Exploitation1Disclosure1
2026-06-121
Active Exploitation1
2026-06-221
Active Exploitation1
2026-06-231
Disclosure1
Full discourse20 posts
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Active Exploitation

    ثغرة Trend Micro Apex One On-Prem رقمها (CVE-2026-34926) مستغلة حاليا من قبل المخترقين ودخلت قائمة (CISA KEV). 📍هذي الثغرة المهاجم يحتاج وصول مسبق للسيرفر بصلاحيات ادمن. يعني السيناريو هنا (Post-compromise). 📍إذا المهاجم عنده صلاحيات (Admin)، يقدر يعدل (Key table) ويحقن كود خبيث يتم توزيعه تلقائياً على كل أجهزة الـ (Agents) المتصلة بالسيرفر.

    Post summary

    CVE-2026-34926 is confirmed to be actively exploited in the wild, as indicated by its inclusion in the CISA KEV list, with attackers requiring admin access to a server to modify the key table and distribute malicious code to connected agents.

    14028212.8K
    50.0K followersView on X
  • CISA Cyber@CISACyber
    Active Exploitation

    🛡️ We added Langflow origin validation error vulnerability CVE-2025-34291 and Trend Micro Apex One (on-premise) server directory traversal vulnerability CVE-2026-34926 to our KEV Catalog. Visit https://go.dhs.gov/Z3Q for more information. #Cybersecurity #InfoSec https://t.co/Ii831YymYf

    Post summary

    The tweet announces that Langflow (CVE-2025-34291) and Trend Micro Apex One (CVE-2026-34926) are added to a KEV catalog, indicating they are actively exploited in the wild.

    711230210.5K
    300.1K followersView on X
  • JPCERTコーディネーションセンター@jpcert
    Active Exploitation

    TrendAI Apex Oneなどのトレンドマイクロ製品における複数の脆弱性に関する注意喚起を公開。TrendAI Apex One(オンプレミス版)において相対パストラバーサルの脆弱性(CVE-2026-34926)を悪用した攻撃が確認されています。早期にパッチ適用などの対応を実施ください。^KK https://www.jpcert.or.jp/at/2026/at260014.html

    Post summary

    The notice confirms exploitation of CVE-2026-34926 in TrendAI Apex One, urging early patching.

    07116219.4K
    34.0K followersView on X
  • Help Net Security@helpnetsecurity
    Active Exploitation

    Actively exploited Trend Micro Apex One flaw gets CISA warning (CVE-2026-34926) - https://www.helpnetsecurity.com/2026/05/26/actively-exploited-trend-micro-apex-one-flaw-cve-2026-34926/ - @trendaisecurity #0day #EndpointSecurity #SecurityUpdate #Cybersecurity #CybersecurityNews https://t.co/V6oqUb0Np6

    Post summary

    The tweet announces that CVE-2026-34926, a flaw in Trend Micro Apex One, is being actively exploited in the wild and has prompted a CISA warning. No PoC, patch, or technical details are offered in the tweet itself.

    01031444
    60.1K followersView on X
  • Aniket Chavan@ianiketchavan
    Active Exploitation

    🚨 Zero-Day Watch Trend Micro Apex One (CVE-2026-34926) has been observed under active exploitation. Priorities: ✔ Validate exposure ✔ Patch affected systems ✔ Review suspicious file access activity ✔ Monitor for lateral movement

    Post summary

    The post alerts that CVE‑2026‑34926 is currently being exploited in the wild and advises patching and monitoring for lateral movement.

    10021191
    662 followersView on X
  • Autumn Good@autumn_good_35
    Active Exploitation

    🚨🚨🚨 『TrendAI Apex One(オンプレミス版)において、相対パストラバーサルの脆弱性(CVE-2026-34926)を悪用した攻撃を確認しているとのことです』 2026-05-21 JPCERT/CC TrendAI Apex Oneなどのトレンドマイクロ製品における複数の脆弱性に関する注意喚起 https://www.jpcert.or.jp/at/2026/at260014.html

    Post summary

    Alert indicates TrendAI Apex One is being targeted via CVE-2026-34926 relative path traversal exploitation; no PoC, patches, or specific exploit tools are referenced.

    00121884
    6.9K followersView on X
  • Elusive@ElusivePrivacy
    Active Exploitation

    Trend Micro Apex One zero-day (CVE-2026-34926) A security product's own zero-day is being exploited in the wild. Trend Micro patched CVE-2026-34926, a directory traversal in Apex One on-prem that lets an attacker with admin credentials inject malicious code deployed to all managed endpoints. Discovered internally by TrendAI's IR team. CISA added to KEV federal patch deadline June 4. Source: SecurityWeek / TrendAI advisory Full analysis → http://t.me/VulnerabilityNews Follow @VulnerabilityNw

    Post summary

    Trend Micro Apex One zero‑day CVE-2026-34926, a directory traversal that lets attackers with admin rights inject code into all endpoints, is actively exploited in the wild. The vendor has supplied a patch and the incident is listed in CISA’s KEV with a federal patch deadline of June 4.

    11010157
    182 followersView on X
  • BnSnK@BunSnack
    Active Exploitation

    Trend Micro Apex One CVE-2026-34926: directory traversal by pre-authenticated local attacker modifies policy table, deploys malicious code to all managed agents. CISA KEV. https://nvd.nist.gov/vuln/detail/CVE-2026-34926

    Post summary

    CISA has flagged CVE-2026-34926 as a known exploited vulnerability, indicating that local attackers can use a directory traversal flaw in Trend Micro Apex One to alter policy tables and deploy malware across all managed agents.

    000209
    6 followersView on X
  • CiberBaur@BotBauR
    Active Exploitation

    Acaba de confirmarse: una vulnerabilidad de día cero en la plataforma Apex One de Trend Micro, identificada como CVE-2026-34926, ha sido explotada en ataques activos. Trend Micro ha confirmado que su plataforma Apex One tiene una vulnerabilidad de directory path traversal, aunque no hay registros públicos de este CVE. Históricamente, Apex One ha sufrido vulnerabilidades de ejecución remota de código y escalada de privilegios. La vulnerabilidad podría permitir a atacantes explotar la plataforma para obtener acceso no autorizado o ejecutar código malicioso. Aunque no hay detalles públicos sobre el CVE, la advertencia de CISA sugiere que la vulnerabilidad es grave y está siendo explotada activamente. No hay parche confirmado para esta vulnerabilidad, pero es crucial que los administradores de sistemas revisen sus configuraciones de seguridad y monitoreen los logs de su plataforma Apex One para detectar cualquier actividad sospechosa. ¿Estás en riesgo? Revisa esto: verifica la versión de tu plataforma Apex One y busca actualizaciones de seguridad. https://www.helpnetsecurity.com/2026/05/26/actively-exploited-trend-micro-apex-one-flaw-cve-2026-34926/

    Post summary

    The text confirms CVE-2026-34926, a directory path traversal flaw in Trend Micro Apex One, is actively exploited in the wild, with no patch confirmed but recommended configuration reviews.

    0101075
    320 followersView on X
  • キタきつね@foxbook
    Active Exploitation

    Trend Micro Apex Oneの脆弱性が悪用され、CISAから警告が発令されました(CVE-2026-34926) Actively exploited Trend Micro Apex One flaw gets CISA warning (CVE-2026-34926) #HelpNetSecurity (May 26) https://www.helpnetsecurity.com/2026/05/26/actively-exploited-trend-micro-apex-one-flaw-cve-2026-34926/

    Post summary

    The text reports that Trend Micro Apex One CVE-2026-34926 is being actively exploited in the wild, prompting a CISA warning.

    01010230
    4.8K followersView on X
  • Adam@seoscottsdale
    Active Exploitation

    Supply-chain surge status as of May 26, 2026 – 100% verified accuracy on Ghost CMS CVE-2026-26980 mass exploitation, Laravel Lang hijack, healthcare vendor breaches & CISA KEV additions; surge accelerating with no new catastrophic incidents in last 48h. 🚨 SUPPLY CHAIN CYBER ATTACK SURGE – MAY 26, 2026 X ARTICLE (100% LIVE-VERIFIED)
Ghost CMS actively exploited on 700+ sites. Laravel Lang packages poisoned. Healthcare vendors leaking PHI. CISA drops fresh KEVs. Accuracy Verdict: 100% Confirmed — Full independent fact-check against BleepingComputer, HIPAA Journal, CISA & threat intel sources. Zero discrepancies. Ready-to-post early-warning for @seoscottsdale & every Arizona team. High-signal facts + urgent actions only. Thread 🧵
#SupplyChainAttack #CyberSecurity #ScottsdaleCyber #PhoenixInfoSec #ArizonaTech 1/9
✅ Ghost CMS CVE-2026-26980 – Mass Exploitation LIVE
Critical SQL injection actively exploited on 700+ sites. Attackers steal Admin API keys → inject malicious JS that triggers ClickFix malware (fake Cloudflare CAPTCHA → PowerShell execution).
Affected: Academia, SaaS, media, fintech.
Severity: High & ongoing.
Source: BleepingComputer (May 24-25, 2026).
Action: Patch immediately + full site integrity audit. 2/9
✅ Laravel Lang Supply-Chain Hijack
Attackers rewrote GitHub version tags to push malicious Composer packages packed with credential-stealing malware.
Affected: Any dev/org using Laravel localization packages.
Impact: Downstream app compromises at scale.
Timeline: May 22-23, 2026.
Source: BleepingComputer.
Action: Audit every Composer dependency and verify signatures NOW. 3/9
✅ Healthcare Vendor & HIPAA Supply-Chain Breaches
• Lumexa Imaging vendor incident
• Radiology Associates of Richmond (266K records exposed) + multiple covered entities
Arizona impact: Scottsdale/Phoenix hospitals, clinics & imaging centers using third-party vendors are in the direct blast radius (HIPAA + AZ breach laws).
Source: HIPAA Journal (May 19-20, 2026). 4/9
✅ CISA Known Exploited Vulnerabilities (KEV) Catalog Updates
Recent additions:
• May 21: CVE-2025-34291 (Langflow) + CVE-2026-34926 (Trend Micro Apex One)
• May 7: CVE-2026-6973 (Ivanti EPMM)
Affected: Federal contractors & enterprises.
Severity: Mandatory patching under BOD 22-01 or face enforcement.
Source: http://CISA.gov/news-events/alerts/ (May 2026). 5/9
✅ Broader Context (SentinelOne & CrowdStrike intel)
No brand-new catastrophic incident in the last 48 hours, but persistent open-source activity (npm/PyPI waves) + active Ghost CMS and Laravel vectors keep the 2026 supply-chain surge elevated. 6/9
Scottsdale/Phoenix 24-Hour Action Checklist 1Run full SBOM scan on every environment 2Audit all CMS, Composer, npm & PyPI dependencies 3Review third-party vendor access & contracts 4Patch every KEV immediately 5Test supply-chain incident response playbooks 7/9
These upstream attacks hit Arizona healthcare, tech firms, SaaS teams, and government contractors the hardest.
The surge isn’t coming — it’s here right now. 8/9
Full Verified Deep-Dive Available
This entire briefing was built live from primary sources and independently accuracy-checked as of 08:35 AM PDT today.
Subscribe for weekly GEO-optimized cyber briefings tailored to the greater Phoenix metro. 9/9
What’s your #1 supply-chain risk right now? Drop it in the replies 👇
RT to protect your network and the Phoenix metro.
@seoscottsdale #InfoSec #ThirdPartyRisk #CyberSurge2026 #ArizonaCyber End of Verified X Article – 100% accurate & ready to post. Stay ahead. Protect the chain.
Sources (all checked live May 26, 2026): http://BleepingComputer.com (May 23–25), http://HIPAAJournal.com (May 19–20), http://CISA.gov (May 2026), SentinelOne & CrowdStrike blogs.

    Post summary

    The post reports that CVE‑2026‑26980 is actively exploited on hundreds of sites, describes the technical nature of the vulnerability, and urges immediate patching, making it an active exploitation alert.

    01010134
    12.4K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🟠 Trend Micro Apex One, Directory Traversal, #CVE-2026-34926 (Medium) https://dailycve.com/trend-micro-apex-one-directory-traversal-cve-2026-34926-medium/

    Post summary

    A new medium‑severity directory traversal vulnerability (CVE‑2026‑34926) affecting Trend Micro Apex One has been disclosed, but no PoC, exploit tool, active exploitation evidence, or patch information is mentioned.

    0101077
    220 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2026-34926: Trend Micro Apex One (on-premise) contains a directory traversal vulnerability that could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations.

    Post summary

    A new directory traversal flaw in Trend Micro Apex One allows local attackers to alter server tables and deploy malicious code to agents, but no PoC, exploit, or active exploitation reports are mentioned.

    1000059
    258 followersView on X
  • Proficio@proficioinc
    Active Exploitation

    U.S. CISA adds Trend Micro Apex One (CVE-2026-34926) and Langflow (CVE-2025-34291) to Known Exploited Vulnerabilities catalog via @SecurityAffairs #Proficio #ThreatNews #Cybersecurity #MSSP #MDR https://securityaffairs.com/192529/hacking/u-s-cisa-adds-trend-micro-apex-one-and-langflow-to-its-known-exploited-vulnerabilities-catalog.html

    Post summary

    CISA has flagged CVE-2026-34926 in Trend Micro Apex One and CVE-2025-34291 in Langflow as being actively exploited, adding them to its Known Exploited Vulnerabilities catalog.

    00010137
    1.0K followersView on X
  • The Cyber Security Hub™@TheCyberSecHub
    Active Exploitation

    Actively exploited Trend Micro Apex One flaw gets CISA warning (CVE-2026-34926) https://www.helpnetsecurity.com/2026/05/26/actively-exploited-trend-micro-apex-one-flaw-cve-2026-34926/?utm_source=dlvr.it&utm_medium=twitter

    Post summary

    The note reports that Trend Micro Apex One CVE-2026-34926 is actively exploited and has triggered a CISA warning, but it lacks details on exploitation methods, patches, or PoCs.

    00010447
    194.6K followersView on X
  • SempreUpdate@SempreUpdate
    Disclosure

    CVE-2026-34926 afeta Trend Micro Apex One https://sempreupdate.com.br/trend-micro-apex-one-vulnerabilidade-zero-day/

    Post summary

    The text announces a zero‑day vulnerability, CVE‑2026‑34926, that affects Trend Micro Apex One.

    00010485
    4.7K followersView on X
  • Cert-IST@cert_ist
    Active Exploitation

    La CISA ajoute la faille Trend Micro Apex One (CVE-2026-34926) activement exploitée à son catalogue KEV : la vulnérabilité transforme la plateforme de sécurité en vecteur de diffusion de malware. Un correctif est disponible. https://tinyurl.com/yc25uzx9

    Post summary

    CISA added Trend Micro Apex One CVE-2026-34926 to its KEV catalog, signifying active exploitation in the wild, and a patch has been released.

    010001.6K
    959 followersView on X
  • NerdieNews@NewsNerdie
    Patch

    🚨 BREAKING: TrendAI has patched a critical zero-day vulnerability, CVE-2026-34926, in Apex One. The flaw allowed directory traversal attacks on the on-premise version, exploited in the wild. Stay updated and secure! #NerdieNews #CyberSecurity #BreakingNews #InfoSec #ZeroDay https://t.co/NRoxmrk7hJ

    Post summary

    TrendAI released a patch for CVE‑2026‑34926, a directory traversal flaw in Apex One that was already being exploited in the wild.

    00010114
    64 followersView on X
  • Eduard Kovacs@EduardKovacs
    Patch

    TrendA has informed customers that it has patched CVE-2026-34926, another Apex One vulnerability that has been exploited in the wild. https://www.securityweek.com/trendai-patches-apex-one-zero-day-exploited-in-the-wild/

    Post summary

    TrendA released a patch for CVE-2026-34926, a previously exploited Apex One vulnerability, underscoring the need for timely application of vendor fixes.

    00010199
    13.8K followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(5/21追加) 🛡️No.1601 CVE-2025-34291 Langflow Origin Validation Error Vulnerability ==================================== ✅概要 ・深刻度:重要 8.8 (CVSS Base) / NVD ・種別:同一生成元ポリシー違反 (CWE-346) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Langflow 1.6.9 以下には、過度に許可された CORS 設定と SameSite=None の refresh token cookie の組み合わせにより、アカウント乗っ取りとリモートコード実行に至る連鎖的な脆弱性が存在します。攻撃者は悪意ある Web ページから被害者セッションに対してクロスオリジン要求を送信し、新しい access token / refresh token を取得できます。取得したトークンで認証済みエンドポイントに到達でき、組み込みのコード実行機能を通じて任意コード実行と全面的なシステム侵害に至る恐れがあります。 ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:中 ✅攻撃前提条件 ・Langflow 1.6.9 以下が稼働していること。 ・標的が Langflow にログイン済みのセッションを保持していること。 ・標的が悪意ある Web ページを閲覧すること。 ・過度に許可された CORS 設定と SameSite=None の refresh token cookie 設定が有効であること。 ✅悪用時影響 ・被害者セッションの fresh access token / refresh token を取得される ・認証済みエンドポイントへ不正アクセスされる ・組み込みのコード実行機能を悪用され、任意のコードを実行される ✅悪用事例等に関する公開情報 ・PoC/Exploit:一部公開(技術情報のみ) ・ITW:確認済み。CrowdSec は 2026年1月23日から本脆弱性のアクティブな悪用を観測したと報告。 ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2025-34291 https://github.com/langflow-ai/langflow https://www.crowdsec.net/vulntracking-report/cve-2025-34291 🛡️No.1602 CVE-2026-34926 Trend Micro Apex One (On-Premise) Directory Traversal Vulnerability ==================================== ・関連ポスト済 https://x.com/piyokango/status/2057634002895540274 https://www.cisa.gov/news-events/alerts/2026/05/21/cisa-adds-two-known-exploited-vulnerabilities-catalog #vulnerability

    Post summary

    CISA has added CVE‑2025‑34291 to its catalog after confirmed active exploitation by CrowdSec; the post includes technical details and a partial PoC, but no patch or exploit code is provided.

    000106.1K
    43.3K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Apptrendmicroapex_one-windows-
Apptrendmicroapex_one-windows-

Explore more