๐ฅ This vulnerability is being actively exploited in the wild (CISA Known Exploited Vulnerabilities catalog)
CVE-2026-34926: Trend Micro Apex One (On-Premise) Directory Traversal Vulnerability
Summary
Trend Micro Apex One (on-premise) has a directory traversal vulnerability (a flaw that lets attackers access files outside their intended directory) that allows a local attacker without authentication to modify a key table on the server and inject malicious code to be sent to managed agents. This vulnerability is currently being actively exploited by attackers.
Solution / Mitigation
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Vulnerability Details
EPSS: 0.0%
Yes
๐ฅ Actively Exploited
May 20, 2026
Classification
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-34926
First tracked: May 21, 2026 at 08:00 PM
Classified by LLM (prompt v3) ยท confidence: 95%